Data Modification Vulnerability in GreenShift Animation and Page Builder Blocks Plugin
CVE-2026-5093
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 August 2026
What is CVE-2026-5093?
The GreenShift β Animation and Page Builder Blocks plugin for WordPress has a security flaw that allows authenticated users, including those with contributor-level access, to modify global theme color settings on the site. This occurs due to a lack of proper capability checks in the 'gspb_update_global_wp_settings' function, which only validates 'edit_posts' capability instead of stricter administrative privileges. This oversight can lead to unauthorized alterations and potential site defacement.
Affected Version(s)
Greenshift β animation and page builder blocks 0 <= 12.8.9