Beta

Report

Greenshift 11.4-11.4.5 is vulnerable to Authenticated (Subscriber+) Arbitrary File Upload vulnerability

Unauthenticated
Published
2025-04-20

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gspb_make_proxy_api_request() function in versions 11.4 to 11.4.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The arbitrary file upload was sufficiently patched in 11.4.5, but a capability check was added in 11.4.6 to properly prevent unauthorized limited file uploads.

CVSS

Score:8.8

Severity:High

Version:11.4-11.4.5

There is a patch available in v11.4.6 and we strongly recommend you update to this version as soon as possible.