SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-5093

MEDIUM · CVSS 4.3 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable due to inadequate capability checks in the 'gspb_update_global_wp_settings' function, allowing authenticated users with contributor-level access or higher to modify global theme color settings. This could lead to unauthorized site defacement, impacting the integrity of the affected WordPress installations. Administrators of sites using versions up to 12.8.9 of this plugin should prioritize applying updates to mitigate this risk.

CVE
CVE-2026-5093
Severity
MEDIUM
CVSS
4.3
EPSS
0.36%
WordPress

Original NVD Description

The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 12.8.9. This is due to a missing capability check on the 'gspb_update_global_wp_settings' function that only verifies the 'edit_posts' capability instead of requiring administrative privileges. This makes it possible for authenticated attackers, with contributor-level access and above, to modify global WordPress theme color settings site-wide, leading to site defacement.