CVE-2024-6155: Greenshift – animation and page builder blocks <= 9.0.0 - Missing Authorization to Authenticated (Subscriber+) Server-Side Request Forgery and Stored Cross-Site Scripting
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Authenticated (Subscriber+) Server-Side Request Forgery and Stored Cross Site Scripting in all versions up to, and including, 9.0.0 due to a missing capability check in the greenshiftdownloadfilelocaly function, along with no SSRF protection and sanitization on uploaded SVG files. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application that can also be leveraged to download malicious SVG files containing Cross-Site Scripting payloads to the server. On Cloud-based servers, attackers could retrieve the instance metadata. The issue was partially patched in version 8.9.9 and fully patched in version 9.0.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6155?
CVE-2024-6155 is classified as a critical vulnerability due to its potential for unauthorized access and exploitation.
What are the implications of CVE-2024-6155 for WordPress sites?
CVE-2024-6155 can lead to Server-Side Request Forgery and Stored Cross Site Scripting, posing significant risks to site security and data integrity.
How do I fix CVE-2024-6155?
To remediate CVE-2024-6155, update the Greenshift animation and page builder blocks plugin to version 9.0.1 or higher immediately.
Who is affected by CVE-2024-6155?
All users of the Greenshift animation and page builder blocks plugin for WordPress running versions up to and including 9.0.0 are affected.
Is authentication required to exploit CVE-2024-6155?
Yes, CVE-2024-6155 requires authenticated access as a Subscriber or higher to exploit the vulnerability.