
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2371 is an Insecure Direct Object Reference (IDOR) vulnerability in the Greenshift – Animation and Page Builder Blocks plugin for WordPress, affecting all versions up to and including 12.8.3. The flaw stems from missing authorization and post status validation in the gspb_el_reusable_load() AJAX handler, allowing unauthenticated attackers to retrieve the rendered HTML content of private, draft, or password-protected reusable blocks. It was published on March 7, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (Red Hat CVE).
The root cause is classified as CWE-862 (Missing Authorization). The gspb_el_reusable_load() AJAX handler accepts an arbitrary post_id parameter and renders the content of any wp_block post without performing a current_user_can('read_post', $post_id) check or verifying the post's publication status. Critically, the nonce required to invoke this handler is exposed to unauthenticated users on any public page that uses the [wp_reusable_render] shortcode with the ajax="1" attribute, effectively bypassing WordPress's nonce-based access control for this endpoint (Red Hat CVE).
Successful exploitation allows unauthenticated remote attackers to read the rendered HTML content of WordPress reusable blocks that are in private, draft, or password-protected states. This represents a confidentiality breach — sensitive content intended to be restricted (e.g., unpublished drafts, internal notes, or password-gated content stored as reusable blocks) can be exposed to any internet user. There is no integrity or availability impact, and lateral movement potential is limited to information disclosure within the WordPress content scope (Red Hat CVE).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.009% (0.000090), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack requires no authentication and no user interaction, but does require the target site to have the [wp_reusable_render] shortcode with ajax="1" deployed on a public page (Red Hat CVE).
[wp_reusable_render] shortcode rendered output.[wp_reusable_render] shortcode with ajax="1". Extract the nonce value from the page's HTML source or inline JavaScript (typically embedded in a localized script variable).post_id values (e.g., starting from 1 upward) to identify wp_block posts. WordPress post IDs are sequential and predictable./wp-admin/admin-ajax.php) with the action set to the handler (e.g., action=gspb_el_reusable_load), the harvested nonce, and the target post_id./wp-admin/admin-ajax.php with action=gspb_el_reusable_load from a single IP or user agent, especially with sequentially incrementing post_id values; requests originating from IPs with no prior site interaction.admin-ajax.php with the Greenshift reusable load action from unauthenticated sessions; requests returning HTTP 200 with non-empty body for post IDs corresponding to non-public posts.wp_block post content in WordPress debug logs if WP_DEBUG_LOG is enabled.Users should update the Greenshift – Animation and Page Builder Blocks plugin to a version beyond 12.8.3 that includes a fix for this vulnerability (check the WordPress plugin repository for the patched release). As a temporary workaround, site administrators can remove or disable any instances of the [wp_reusable_render] shortcode with ajax="1" from public-facing pages, which eliminates the nonce exposure vector and prevents unauthenticated exploitation. Additionally, restricting access to wp-admin/admin-ajax.php for unauthenticated users via WAF rules or server configuration can reduce exposure (Red Hat CVE, Sucuri Blog).
Sucuri included CVE-2026-2371 in their March 2026 vulnerability patch roundup, noting it as part of a broader set of WordPress plugin issues requiring attention (Sucuri Blog). The vulnerability was also tracked by threat intelligence platforms including VulDB, CIRCL, and ENISA's EUVD shortly after disclosure, reflecting standard community monitoring of medium-severity WordPress plugin flaws. No notable researcher commentary or significant social media discussion beyond automated CVE tracking has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."