SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-83544

MEDIUM · CVSS 6.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Greenshift WordPress plugin prior to version 13.2.0 is vulnerable due to improper escaping of a block animation attribute, enabling users with contributor-level access and higher to inject malicious web scripts into HTML attributes. This vulnerability could lead to cross-site scripting (XSS) attacks, compromising the integrity of the website and potentially affecting its users. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-83544
Severity
MEDIUM
CVSS
6.8
EPSS
0.24%
WordPress

Original NVD Description

The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed.