{"apiVersion":"1.0","identifier":"CVE-2026-5093","description":"The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 12.8.9. This is due to a missing capability check on the -gspb_update_global_wp_settings- function that only verifies the -edit_posts- capability instead of requiring administrative privileges. This makes it possible for authenticated attackers, with contributor-level access and above, to modify global WordPress theme color settings site-wide, leading to site defacement.","publishedAt":"2026-08-22T14:16:33","lastModifiedAt":"2026-08-24T16:41:13","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-5093","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","epssProbability":0.00355,"riskScore":0.44,"affectedProduct":"GreenShift – Animation and Page Builder Blocks","affectedVersions":"<=12.8.9","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-5093","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-5093","en":"https://www.redsauce.net/en/cves/CVE-2026-5093","fr":"https://www.redsauce.net/fr/cves/CVE-2026-5093","pt":"https://www.redsauce.net/pt/cves/CVE-2026-5093","de":"https://www.redsauce.net/de/cves/CVE-2026-5093","sk":"https://www.redsauce.net/sk/cves/CVE-2026-5093","el":"https://www.redsauce.net/el/cves/CVE-2026-5093"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-5093"}}