Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12330 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gspb_make_proxy_api_request() function in versions 11.4 to 11.4.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The arbitrary file upload was sufficiently patched in 11.4.5, but a capability check was added in 11.4.6 to properly prevent unauthorized limited file uploads. |
Wed, 28 May 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Greenshiftwp
Greenshiftwp greenshift - Animation And Page Builder Blocks |
|
| CPEs | cpe:2.3:a:greenshiftwp:greenshift_-_animation_and_page_builder_blocks:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Greenshiftwp
Greenshiftwp greenshift - Animation And Page Builder Blocks |
Tue, 22 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Apr 2025 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gspb_make_proxy_api_request() function in versions 11.4 to 11.4.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The arbitrary file upload was sufficiently patched in 11.4.5, but a capability check was added in 11.4.6 to properly prevent unauthorized limited file uploads. | |
| Title | Greenshift 11.4 - 11.4.5 - Authenticated (Subscriber+) Arbitrary File Upload | |
| Weaknesses | CWE-434 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-04-22T13:17:08.386Z
Reserved: 2025-04-14T21:53:28.375Z
Link: CVE-2025-3616
Updated: 2025-04-22T13:17:03.578Z
Status : Analyzed
Published: 2025-04-22T05:15:30.780
Modified: 2025-05-28T17:38:29.717
Link: CVE-2025-3616
No data.
OpenCVE Enrichment
No data.
EUVD