#CVE-2025-3616
🚨 CVE-2025-3616 in Greenshift WP plugin allows RCE via subscriber uploads. 

Update to v11.4.6+ now. 

Try with Modat Magnify: 

Run → technology="WordPress" web.html~"greenshift" 
magnify.modat.io 


#ModatMagnify #WordPress #RCE #CVE-2025-3616
Modat Magnify
magnify.modat.io
April 23, 2025 at 8:05 AM
Critical alert: Greenshift WordPress plugin (CVE-2025-3616) allows file uploads leading to RCE. Affects 50K+ sites on versions 11.4-11.4.5. Patch now to 11.4.6. Details: Read More
April 22, 2025 at 10:12 AM
CVE-2025-3616 - Greenshift WordPress Animation and Page Builder Blocks Unvalidated File Upload Vulnerability
CVE ID : CVE-2025-3616

Published : April 22, 2025, 5:15 a.m. | 1 hour, 44 minutes ago

Description : The Greenshift – animation and page builder blocks plugin for ...
CVE-2025-3616 - Greenshift WordPress Animation and Page Builder Blocks Unvalidated File Upload Vulnerability
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gspb_make_proxy_api_request() function in versions 11.4 to 11.4.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the …
cvefeed.io
April 22, 2025 at 7:04 AM
You can now share your thoughts on vulnerability CVE-2025-3616 in Vulnerability-Lookup:
https://vulnerability.circl.lu/vuln/CVE-2025-3616

wpsoul - Greenshift – animation and page builder blocks

#vulnerabilitylookup #vulnerability #cybersecurity #bot
cvelistv5 - CVE-2025-3616
Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.
vulnerability.circl.lu
April 22, 2025 at 4:57 AM