CVE-2026-5093: CWE-862 Missing Authorization in wpsoul Greenshift – animation and page builder blocks
Description
The GreenShift – Animation and Page Builder Blocks WordPress plugin versions up to 12.8.9 contain a missing authorization vulnerability. Authenticated users with contributor-level access or higher can modify global WordPress theme color settings site-wide due to insufficient capability checks in the 'gspb_update_global_wp_settings' function. This can lead to site defacement.
CVSS v3.1
Score 4.3medium
Affected software
wpsoul
Greenshift – animation and page builder blocks
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-5093 is a missing authorization vulnerability (CWE-862) in the GreenShift – Animation and Page Builder Blocks plugin for WordPress. The vulnerability arises because the 'gspb_update_global_wp_settings' function only checks for the 'edit_posts' capability, which contributors and above possess, instead of requiring administrative privileges. This allows authenticated users with contributor-level access or higher to modify global theme color settings across the site, potentially causing site defacement. The issue affects all plugin versions from 0 up to and including 12.8.9.
Potential Impact
An attacker with contributor-level or higher authenticated access can modify global WordPress theme color settings site-wide, which may result in site defacement. There is no impact on confidentiality or availability reported. The CVSS v3.1 base score is 4.3 (medium severity), reflecting low complexity and limited impact confined to integrity.
Mitigation Recommendations
No official patch or fix is currently documented. Users should restrict contributor-level access and above to trusted individuals until a fix is released. Monitor vendor advisories for updates. Since this is not a cloud service, remediation depends on applying vendor patches when available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-03-29T04:54:52.335Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a89a625acd9273b49149cc1
Added to database: 08/22/2026, 13:37:41 UTC
Last enriched: 09/11/2026, 02:02:39 UTC
Last updated: 10/06/2026, 06:48:19 UTC
Views: 61
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.