CVE-2026-2589: Wpsoul Greenshift – Animation And Page Builder Blocks
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 12.8.3 via the automated Settings Backup stored in a publicly accessible file. This makes it possible for unauthenticated attackers to extract sensitive data including the configured OpenAI, Claude, Google Maps, Gemini, DeepSeek, and Cloudflare Turnstile API keys.
Affected products
- Wpsoul Greenshift – Animation And Page Builder Blocks: up to and including 12.8.3
Published 2026-03-06. Last modified 2026-06-17.