CVE-2025-3616 is an arbitrary file upload vulnerability in the Greenshift – animation and page builder blocks plugin for WordPress, affecting versions 11.4 to 11.4.5. The vulnerability is due to missing file type validation in the gspb_make_proxy_api_request() function, allowing authenticated users with Subscriber-level access or higher to upload arbitrary files to the server. This can potentially lead to remote code execution if a malicious file is uploaded and executed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Metasploit exploit module plus a README. The module (wp_greenshift_file_upload.rb) targets CVE-2025-3616 in the WordPress Greenshift plugin versions 11.4.0–11.4.5, exploiting an authenticated arbitrary file upload in the REST route /wp-json/greenshift/v1/proxy-api (via the plugin's gspb_make_proxy_api_request functionality). The exploit workflow is: (1) optionally fingerprint the plugin version by requesting /wp-content/plugins/greenshift-animation-and-page-builder-blocks/readme.txt and parsing the 'Stable tag'; (2) obtain an authenticated session either by logging in at /wp-login.php with USERNAME/PASSWORD or by registering a new user at /wp-login.php?action=register when registration is enabled; (3) fetch /wp-admin/post-new.php and scrape a 10-hex WP REST nonce from wpApiSettings to use as X-WP-Nonce; (4) upload a randomly named .php file using multipart/form-data where the file part is labeled image/gif and the content is prefixed with GIF89a; to bypass finfo_file() MIME validation; (5) parse JSON response for file_url and then trigger the uploaded payload with an HTTP GET to achieve RCE. The module uses Metasploit's HttpClient and FileDropper (register_file_for_cleanup) and is designed for remote network exploitation against a WordPress web application.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.