Executive brief
GreenShift is a popular WordPress plugin that provides animation and page builder functionality. A flaw in the plugin's capability checks allows authenticated users with basic contributor permissions to modify global WordPress theme color settings across the entire site, causing visual defacement and damaging site appearance and brand consistency.
Technical details
The vulnerability is a privilege escalation (authorization bypass) in the 'gspb_update_global_wp_settings' function due to insufficient capability checks. The function verifies only the 'edit_posts' capability, which is granted to contributor-level users and above, instead of requiring administrative ('manage_options') privileges. This allows an authenticated attacker with contributor access or higher to make network-reachable requests modifying global WordPress theme color settings site-wide. No user interaction or additional preconditions are required beyond initial authentication. The impact is limited to site defacement through theme color manipulation; no data exfiltration or service disruption occurs.
Affected products
- Amp Project GreenShift – Animation and Page Builder Blocks up to and including 12.8.9
Timeline
- 2026-08-22: disclosed