Sceawere
Vulnerability Detail
CVE-2026-93880UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Greenshift Reflected XSS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.1
- Creation Date
- 15h ago
- Vendor
- wpsoul
- Product
- Greenshift – animation and page builder blocks
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder in all versions up to, and including, 13.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This requires a site administrator to have configured an element block's Custom JS field to include a {{GET:...}} placeholder and for that JS to contain the token 'import', which routes the substituted value to the unescaped raw echo branch inside a <script type="module"> tag.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.1",
"pubDate": "2026-10-02T08:17:03.413Z",
"pubdate": "2026-10-02T08:17:03.413Z",
"executiveSummary": "The Greenshift – animation and page builder blocks plugin for WordPress contains a Reflected Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 13.2.0.\nThis vulnerability stems from insufficient input sanitization and output escaping within the plugin's dynamic placeholder functionality.\nThe flaw allows unauthenticated attackers to execute arbitrary malicious JavaScript in the context of a victim's browser session, provided the attacker can induce a user to interact with a crafted URL.\nExploitation is contingent upon a specific configuration where a site administrator has utilized the '{{GET:}}' dynamic placeholder within an element block's Custom JS field, and the script includes the 'import' token.\nSuccessful exploitation results in the execution of unauthorized scripts, which can lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim.\nGiven the requirement for specific block configurations, the risk is elevated for sites utilizing dynamic content injection features, necessitating prompt remediation.",
"technicalDetails": "The vulnerability is rooted in the insecure handling of the '{{GET:}}' dynamic placeholder within the Greenshift plugin’s rendering engine. When this placeholder is processed, the plugin retrieves values from the GET superglobal and performs insufficient sanitization or escaping before injecting them into the DOM.\nSpecifically, the flaw manifests when the '{{GET:}}' placeholder is placed within a 'Custom JS' field of an element block. The plugin's internal logic contains a conditional branch that evaluates the injected code; if the generated JavaScript contains the string 'import', the application routes the substituted value to an unescaped raw echo process.\nThis raw echo occurs within a <script type=\"module\"> tag. Because the data is echoed directly without adequate context-aware sanitization, an attacker can manipulate the input to break out of the intended JavaScript string or execution context, facilitating the injection of arbitrary malicious code.\nThe attack flow proceeds as follows: First, an attacker identifies a page utilizing a Greenshift block configured with the vulnerable '{{GET:}}' placeholder. Second, the attacker crafts a malicious URL containing a GET parameter corresponding to the placeholder. This parameter contains an XSS payload designed to execute when reflected back to the browser.\nThird, the attacker leverages social engineering to entice an authenticated user or administrator to visit the crafted URL. Upon loading the page, the server-side script substitutes the malicious parameter into the 'Custom JS' field. Fourth, because the script contains the 'import' token, the browser processes the module script, executing the attacker-supplied payload within the security context of the victim's session.\nThis reflected XSS vulnerability effectively bypasses intended input filtering, allowing for the execution of arbitrary JavaScript. The impact is significant as it permits attackers to steal session cookies, perform unauthorized actions on the WordPress dashboard if the victim is an administrator, or redirect users to malicious domains. The vulnerability remains present in all versions up to 13.2.0 due to the lack of strict context-dependent output encoding for dynamic placeholders within module-based script tags."
}