CVE-2026-83544: Greenshift < 13.2.0 - Contributor+ Stored XSS via Block Animation customProps Attribute
Published Sep 5, 2026
·Updated
The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed.
Affected Software
1 affected component
Greenshift Greenshift WordPress plugin<13.2.0
Event History
Sep 5, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A user with contributor-level access or higher can inject the malicious content. Exploitation therefore requires an authenticated WordPress account with at least Contributor permissions.
2
When does the injected script execute?
The script executes when someone views content containing the malicious block animation attribute. This can affect other users who view the compromised post or page.
3
Which versions should be remediated?
Greenshift versions earlier than 13.2.0 are affected. Update the plugin to version 13.2.0 or later.