PT-2026-6555 · WordPress · Greenshift

Ismailshadow

·

Published

2026-02-05

·

Updated

2026-03-03

·

CVE-2026-1927

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Greenshift – animation and page builder blocks plugin for WordPress versions through 12.5.7
Description The plugin is susceptible to unauthorized data access because of a missing capability check within the greenshift app pass validation() function. Attackers with Subscriber-level access or higher can retrieve global plugin settings, including stored AI API keys.
Recommendations Update to a version beyond 12.5.7.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-1927

Affected Products

Greenshift