CVE-2025-49301: WordPress Greenshift plugin <= 11.5.5 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows DOM-Based XSS. This issue affects Greenshift: from n/a through 11.5.5.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows DOM-Based XSS.This issue affects Greenshift: from n/a through <= 11.5.5.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49301?
The severity of CVE-2025-49301 is classified as high due to the potential for DOM-Based Cross-site Scripting (XSS).
How do I fix CVE-2025-49301?
To fix CVE-2025-49301, upgrade your Greenshift plugin to version 11.5.6 or higher to eliminate the vulnerability.
What versions are affected by CVE-2025-49301?
CVE-2025-49301 affects all versions of Greenshift up to and including 11.5.5.
Is CVE-2025-49301 related to WordPress?
Yes, CVE-2025-49301 affects the Greenshift plugin for WordPress.
What type of vulnerability is CVE-2025-49301?
CVE-2025-49301 is categorized as a Cross-site Scripting (XSS) vulnerability.