Greenshift – animation and page builder blocks

Vulnerabilities 25Slug greenshift-animation-and-page-builder-blocksLatest version 12.9.6WordPress.org →

Minimum safe version

12.9.0

Update to 12.9.0 or later to address 25 fixable vulnerabilities

Latest available12.9.6
N/A
2026-02-05< 12.6.1

GreenShift - Animation and Page Builder Blocks <= 12.6 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure of AI API Keys and Stored Cross-Site Scripting via custom_css

N/A
2026-03-05< 12.8.4

Greenshift – animation and page builder blocks <= 12.8.3 - Unauthenticated Sensitive Information Exposure via Settings Backup

N/A
2026-03-05< 12.8.6

Greenshift – animation and page builder blocks <= 12.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

N/A
2026-03-06< 12.8.4

Greenshift <= 12.8.3 - Missing Authorization to Unauthenticated Private Reusable Block Disclosure via 'gspb_el_reusable_load'

Medium 6.4
2026-04-11< 12.9.0

Greenshift <= 12.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via disablelazy Attribute

High 8.8
2025-04-21< 11.4.6

Greenshift 11.4 - 11.4.5 - Authenticated (Subscriber+) Arbitrary File Upload

Medium 5.4
2025-01-08< 9.0.1

Greenshift – animation and page builder blocks <= 9.0.0 - Missing Authorization to Authenticated (Subscriber+) Server-Side Request Forgery and Stored Cross-Site Scripting

Medium 6.3
2024-10-16< 1.1.6

Freemius SDK <= 2.4.2 - Missing Authorization Checks

High 7.2
2024-12-13< 7.6.3

WordPress Greenshift – animation and page builder blocks Plugin <= 7.6.2 is vulnerable to Arbitrary File Upload

N/A
2023-07-19< 4.8.1

WordPress Greenshift – animation and page builder blocks Plugin <= 2.8.4 is vulnerable to Cross Site Scripting (XSS)

N/A
2022-03-04< 1.1.6

Freemius SDK <= 2.4.2 - Missing Authorization Checks

N/A
2022-02-28< 1.1.4

WordPress Greenshift – animation and page builder blocks plugin < 1.1.4 - Sensitive Information Disclosure vulnerability

N/A
2022-02-28< 1.1.4

WordPress Greenshift – animation and page builder blocks plugin < 1.1.4 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability