Stored Cross-Site Scripting Vulnerability in Greenshift Plugin for WordPress
CVE-2026-5092
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 August 2026
What is CVE-2026-5092?
The Greenshift β Animation and Page Builder Blocks plugin for WordPress is susceptible to Stored Cross-Site Scripting through its customapi action handler. This vulnerability arises from inadequate sanitization of API responses before they are rendered using the innerHTML property. As a result, authenticated users with Contributor-level access or higher can exploit this flaw to inject arbitrary scripts into pages, leading to potential execution whenever another user accesses the affected page. This poses significant security risks to the integrity of the WordPress sites using this plugin.
Affected Version(s)
Greenshift β animation and page builder blocks 0 <= 12.8.9
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Athiwat Tiprasaharn (Jitlada)
Itthidej Aramsri (Boeing777)