CVE-2026-4895 | wpsoul Greenshift Plugin up to 12.8.9 on WordPress HTML Attribute gspb_greenShift_block_script_assets disablelazy HTML injection (EUVD-2026-21647)
A vulnerability was found in wpsoul Greenshift Plugin up to 12.8.9 on WordPress. It has been classified as problematic. Affected is the function gspb_greenShift_block_script_assets of the component HTML Attribute Handler. Performing a manipulation of the argument disablelazy results in HTML injection.
This vulnerability is cataloged as CVE-2026-4895. It is possible to initiate the attack remotely. There is no exploit available.