Junglewise Threat Intelligence

CVE-2026-5093: GreenShift Animation and Page Builder Blocks privilege escalation in theme settings

CVE-2026-5093 · Severity: medium · CVSS 4.3 · Published 2026-08-22

Executive brief

GreenShift is a popular WordPress plugin that provides animation and page builder functionality. A flaw in the plugin's capability checks allows authenticated users with basic contributor permissions to modify global WordPress theme color settings across the entire site, causing visual defacement and damaging site appearance and brand consistency.

Technical details

The vulnerability is a privilege escalation (authorization bypass) in the 'gspb_update_global_wp_settings' function due to insufficient capability checks. The function verifies only the 'edit_posts' capability, which is granted to contributor-level users and above, instead of requiring administrative ('manage_options') privileges. This allows an authenticated attacker with contributor access or higher to make network-reachable requests modifying global WordPress theme color settings site-wide. No user interaction or additional preconditions are required beyond initial authentication. The impact is limited to site defacement through theme color manipulation; no data exfiltration or service disruption occurs.

Affected products

  • Amp Project GreenShift – Animation and Page Builder Blocks up to and including 12.8.9

Timeline

  • 2026-08-22: disclosed

References