CVE-2024-6155: Greenshift – animation and page builder blocks <= 9.0.0 - Missing Authorization to Authenticated (Subscriber+) Server-Side Request Forgery and Stored Cross-Site Scripting

Published Jan 9, 2025
·
Updated

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Authenticated (Subscriber+) Server-Side Request Forgery and Stored Cross Site Scripting in all versions up to, and including, 9.0.0 due to a missing capability check in the greenshiftdownloadfilelocaly function, along with no SSRF protection and sanitization on uploaded SVG files. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application that can also be leveraged to download malicious SVG files containing Cross-Site Scripting payloads to the server. On Cloud-based servers, attackers could retrieve the instance metadata. The issue was partially patched in version 8.9.9 and fully patched in version 9.0.1.

Affected Software

2 affected components
Greenshiftwp Greenshift - Animation And Page Builder Blocks Wordpress<9.0.1
Greenshift animation and page builder blocks<=9.0.0

Event History

Jan 9, 2025
CVE Published
via MITRE·11:11 AM
Data Sourced
via MITRE·11:11 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2024-6155?

CVE-2024-6155 is classified as a critical vulnerability due to its potential for unauthorized access and exploitation.

2

What are the implications of CVE-2024-6155 for WordPress sites?

CVE-2024-6155 can lead to Server-Side Request Forgery and Stored Cross Site Scripting, posing significant risks to site security and data integrity.

3

How do I fix CVE-2024-6155?

To remediate CVE-2024-6155, update the Greenshift animation and page builder blocks plugin to version 9.0.1 or higher immediately.

4

Who is affected by CVE-2024-6155?

All users of the Greenshift animation and page builder blocks plugin for WordPress running versions up to and including 9.0.0 are affected.

5

Is authentication required to exploit CVE-2024-6155?

Yes, CVE-2024-6155 requires authenticated access as a Subscriber or higher to exploit the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203