What the vulnerability does
01Description
Incorrect Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Greenshift: from n/a through <= 9.7.
Explanation of Vulnerability in Simple Terms
02Summary
Greenshift contains an authorization flaw that allows authenticated users with low privileges to read or modify data they should not have access to. The vulnerability affects versions 0 through 9.7. An attacker with a valid user account can exploit this to view or alter sensitive information within the application's scope.
What an attacker can do
03Attacker Capabilities
Read or modify data belonging to other users or restricted areas of the application.
Potential impact on your site
04Site Impact
Unauthorized data disclosure or modification by authenticated users; confidentiality and integrity of user data at risk.
Conditions required to exploit
05Prerequisites
Attacker must have a valid user account with low-level privileges; no user interaction required.
Key dates
06Disclosure timeline
October 30, 2024
CVE published
May 13, 2026
Record updated