CVE-2026-2371: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-2371 is an Insecure Direct Object Reference (IDOR) vulnerability in the Greenshift – Animation and Page Builder Blocks plugin for WordPress, affecting all versions up to and including 12.8.3. The flaw stems from missing authorization and post status validation in the gspb_el_reusable_load() AJAX handler, allowing unauthenticated attackers to retrieve the rendered HTML content of private, draft, or password-protected reusable blocks. It was published on March 7, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (Red Hat CVE).

Technical details

The root cause is classified as CWE-862 (Missing Authorization). The gspb_el_reusable_load() AJAX handler accepts an arbitrary post_id parameter and renders the content of any wp_block post without performing a current_user_can('read_post', $post_id) check or verifying the post's publication status. Critically, the nonce required to invoke this handler is exposed to unauthenticated users on any public page that uses the [wp_reusable_render] shortcode with the ajax="1" attribute, effectively bypassing WordPress's nonce-based access control for this endpoint (Red Hat CVE).

Impact

Successful exploitation allows unauthenticated remote attackers to read the rendered HTML content of WordPress reusable blocks that are in private, draft, or password-protected states. This represents a confidentiality breach — sensitive content intended to be restricted (e.g., unpublished drafts, internal notes, or password-gated content stored as reusable blocks) can be exposed to any internet user. There is no integrity or availability impact, and lateral movement potential is limited to information disclosure within the WordPress content scope (Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.009% (0.000090), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack requires no authentication and no user interaction, but does require the target site to have the [wp_reusable_render] shortcode with ajax="1" deployed on a public page (Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Greenshift plugin (versions ≤ 12.8.3) by inspecting page source for Greenshift-specific CSS classes, script handles, or the [wp_reusable_render] shortcode rendered output.
  2. Nonce Harvesting: Visit any public page on the target site that renders the [wp_reusable_render] shortcode with ajax="1". Extract the nonce value from the page's HTML source or inline JavaScript (typically embedded in a localized script variable).
  3. Enumerate Post IDs: Iterate over numeric post_id values (e.g., starting from 1 upward) to identify wp_block posts. WordPress post IDs are sequential and predictable.
  4. Send Malicious AJAX Request: Submit an HTTP POST request to the WordPress AJAX endpoint (/wp-admin/admin-ajax.php) with the action set to the handler (e.g., action=gspb_el_reusable_load), the harvested nonce, and the target post_id.
  5. Retrieve Restricted Content: Parse the server's response to obtain the rendered HTML of private, draft, or password-protected reusable blocks, exposing any sensitive content stored within them (Red Hat CVE).

Indicators of compromise

  • Network: Repeated POST requests to /wp-admin/admin-ajax.php with action=gspb_el_reusable_load from a single IP or user agent, especially with sequentially incrementing post_id values; requests originating from IPs with no prior site interaction.
  • Logs: WordPress or web server access logs showing high-frequency AJAX calls to admin-ajax.php with the Greenshift reusable load action from unauthenticated sessions; requests returning HTTP 200 with non-empty body for post IDs corresponding to non-public posts.
  • Application: Unexpected access to wp_block post content in WordPress debug logs if WP_DEBUG_LOG is enabled.

Mitigation and workarounds

Users should update the Greenshift – Animation and Page Builder Blocks plugin to a version beyond 12.8.3 that includes a fix for this vulnerability (check the WordPress plugin repository for the patched release). As a temporary workaround, site administrators can remove or disable any instances of the [wp_reusable_render] shortcode with ajax="1" from public-facing pages, which eliminates the nonce exposure vector and prevents unauthenticated exploitation. Additionally, restricting access to wp-admin/admin-ajax.php for unauthenticated users via WAF rules or server configuration can reduce exposure (Red Hat CVE, Sucuri Blog).

Community reactions

Sucuri included CVE-2026-2371 in their March 2026 vulnerability patch roundup, noting it as part of a broader set of WordPress plugin issues requiring attention (Sucuri Blog). The vulnerability was also tracked by threat intelligence platforms including VulDB, CIRCL, and ENISA's EUVD shortly after disclosure, reflecting standard community monitoring of medium-severity WordPress plugin flaws. No notable researcher commentary or significant social media discussion beyond automated CVE tracking has been identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management