GreenShift - Animation and Page Builder Blocks <= 12.6 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure of AI API Keys and Stored Cross-Site Scripting via custom_css
Greenshift – animation and page builder blocks
Minimum safe version
12.9.0
Update to 12.9.0 or later to address 25 fixable vulnerabilities
Greenshift – animation and page builder blocks <= 12.8.3 - Unauthenticated Sensitive Information Exposure via Settings Backup
Greenshift – animation and page builder blocks <= 12.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Greenshift <= 12.8.3 - Missing Authorization to Unauthenticated Private Reusable Block Disclosure via 'gspb_el_reusable_load'
Greenshift <= 12.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via disablelazy Attribute
CVE-2025-11841
CVE-2025-57884
CVE-2025-49301
Greenshift 11.4 - 11.4.5 - Authenticated (Subscriber+) Arbitrary File Upload
CVE-2025-30873
CVE-2025-26884
Greenshift – animation and page builder blocks <= 9.0.0 - Missing Authorization to Authenticated (Subscriber+) Server-Side Request Forgery and Stored Cross-Site Scripting
CVE-2024-11181
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-50419
CVE-2024-44005
CVE-2024-35765
WordPress Greenshift – animation and page builder blocks Plugin <= 7.6.2 is vulnerable to Arbitrary File Upload
WordPress Greenshift – animation and page builder blocks Plugin <= 2.8.4 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-0378
CVE-2023-22707
CVE-2022-4653
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Greenshift – animation and page builder blocks plugin < 1.1.4 - Sensitive Information Disclosure vulnerability
WordPress Greenshift – animation and page builder blocks plugin < 1.1.4 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability