CyberRota Analysis
AI-GeneratedThe GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable due to inadequate capability checks in the 'gspb_update_global_wp_settings' function, allowing authenticated users with contributor-level access or higher to modify global theme color settings. This could lead to unauthorized site defacement, impacting the integrity of the affected WordPress installations. Administrators of sites using versions up to 12.8.9 of this plugin should prioritize applying updates to mitigate this risk.
Original NVD Description
The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 12.8.9. This is due to a missing capability check on the 'gspb_update_global_wp_settings' function that only verifies the 'edit_posts' capability instead of requiring administrative privileges. This makes it possible for authenticated attackers, with contributor-level access and above, to modify global WordPress theme color settings site-wide, leading to site defacement.