PT-2025-3679 · WordPress · The Greenshift

Arkadiusz Hydzik

·

Published

2025-01-09

·

Updated

2025-06-05

·

CVE-2024-6155

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Greenshift – animation and page builder blocks plugin for WordPress versions prior to 9.0.1
Description The issue is related to Authenticated Server-Side Request Forgery and Stored Cross Site Scripting due to a missing capability check in the greenshift download file localy function, along with no SSRF protection and sanitization on uploaded SVG files. This allows authenticated attackers with Subscriber-level access and above to make web requests to arbitrary locations and download malicious SVG files containing Cross-Site Scripting payloads to the server. On Cloud-based servers, attackers could retrieve the instance metadata.
Recommendations For versions prior to 9.0.1, update to version 9.0.1 or later to resolve the issue. As a temporary workaround, consider disabling the greenshift download file localy function until a patch is available. Restrict access to uploaded SVG files to minimize the risk of exploitation. Avoid using the vulnerable function to download files from arbitrary locations until the issue is resolved.

Fix

Missing Authorization

XSS

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-6155

Affected Products

The Greenshift