cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forgreenshift-animation-and-page-builder-blocks greenshift-animation-and-page-builder-blocks

Direction: ascending
Jun 07, 2024

Greenshift – animation and page builder blocks # cb5648db5073ddd604f4a58da2a251643969c91b

Date
Feb 28, 2022
Research Description
Greenshift &#8211; animation and page builder blocks [greenshift-animation-and-page-builder-blocks] < 1.1.4 WordPress Greenshift – animation and page builder blocks plugin < 1.1.4 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Greenshift – animation and page builder blocks plugin (versions < 1.1.4).
Affected versions
Min -, max -.
Status
vulnerable

Greenshift &#8211; animation and page builder blocks # CVE-2023-6636

CVE, Research URL

CVE-2023-6636

Date
Jan 11, 2024
Research Description
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the 'gspb_save_files' function in versions up to, and including, 7.6.2. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected versions
Min -, max -.
Status
vulnerable

Greenshift &#8211; animation and page builder blocks # CVE-2022-4653

CVE, Research URL

CVE-2022-4653

Date
Jan 16, 2023
Research Description
The Greenshift WordPress plugin before 4.8.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
Affected versions
Min -, max -.
Status
vulnerable

Greenshift &#8211; animation and page builder blocks # CVE-2023-22707

CVE, Research URL

CVE-2023-22707

Date
Mar 27, 2023
Research Description
Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift – animation and page builder blocks plugin <= 4.9.9 versions.
Affected versions
Min -, max -.
Status
vulnerable

Greenshift &#8211; animation and page builder blocks # CVE-2023-0378

CVE, Research URL

CVE-2023-0378

Date
Feb 21, 2023
Research Description
The Greenshift WordPress plugin before 5.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected versions
Min -, max -.
Status
vulnerable
Jun 21, 2024

Greenshift &#8211; animation and page builder blocks # CVE-2024-35765

CVE, Research URL

CVE-2024-35765

Date
Jun 19, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wpsoul Greenshift – animation and page builder blocks allows Stored XSS.This issue affects Greenshift – animation and page builder blocks: from n/a through 8.8.9.1.
Affected versions
Min -, max -.
Status
vulnerable
Sep 19, 2024

Greenshift &#8211; animation and page builder blocks # CVE-2024-44005

CVE, Research URL

CVE-2024-44005

Date
Sep 18, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wpsoul Greenshift – animation and page builder blocks allows Stored XSS.This issue affects Greenshift – animation and page builder blocks: from n/a through 9.3.7.
Affected versions
Min -, max -.
Status
vulnerable
Oct 28, 2024

Greenshift &#8211; animation and page builder blocks # CVE-2024-50419

CVE, Research URL

CVE-2024-50419

Date
Oct 30, 2024
Research Description
Incorrect Authorization vulnerability in Wpsoul Greenshift – animation and page builder blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Greenshift – animation and page builder blocks: from n/a through 9.7.
Affected versions
Min -, max -.
Status
vulnerable
Dec 12, 2024

Greenshift &#8211; animation and page builder blocks # CVE-2024-11181

CVE, Research URL

CVE-2024-11181

Date
Dec 12, 2024
Research Description
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 9.9.9.3 via the 'wp_reusable_render' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to.
Affected versions
Min -, max -.
Status
vulnerable
Jan 10, 2025

Greenshift &#8211; animation and page builder blocks # CVE-2024-6155

CVE, Research URL

CVE-2024-6155

Date
Jan 09, 2025
Research Description
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Authenticated (Subscriber+) Server-Side Request Forgery and Stored Cross Site Scripting in all versions up to, and including, 9.0.0 due to a missing capability check in the greenshift_download_file_localy function, along with no SSRF protection and sanitization on uploaded SVG files. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application that can also be leveraged to download malicious SVG files containing Cross-Site Scripting payloads to the server. On Cloud-based servers, attackers could retrieve the instance metadata. The issue was partially patched in version 8.9.9 and fully patched in version 9.0.1.
Affected versions
Min -, max -.
Status
vulnerable
Feb 27, 2025

Greenshift &#8211; animation and page builder blocks # CVE-2025-26884

CVE, Research URL

CVE-2025-26884

Date
Feb 25, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows Stored XSS. This issue affects Greenshift: from n/a through 10.8.
Affected versions
Min -, max -.
Status
vulnerable
Apr 03, 2025

Greenshift &#8211; animation and page builder blocks # CVE-2025-30873

CVE, Research URL

CVE-2025-30873

Date
Mar 27, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows Stored XSS. This issue affects Greenshift: from n/a through 11.0.2.
Affected versions
Min -, max -.
Status
vulnerable
Apr 29, 2025

Greenshift &#8211; animation and page builder blocks # CVE-2025-3616

CVE, Research URL

CVE-2025-3616

Date
Apr 22, 2025
Research Description
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gspb_make_proxy_api_request() function in versions 11.4 to 11.4.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The arbitrary file upload was sufficiently patched in 11.4.5, but a capability check was added in 11.4.6 to properly prevent unauthorized limited file uploads.
Affected versions
Min -, max -.
Status
vulnerable