← WordPress Vulnerabilities
WordPress security by component

Animation Addons for Elementor

Animation Addons for Elementor is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Jul 30, 2026; the highest published CVSS base score is 6.5.

Plugin slug: animation-addons-for-elementor

CVE-2026-13330: Animation Addons lets authors upload executable SVG files

Animation Addons for Elementor before 2.7.0 unconditionally adds SVG and SVGZ to WordPress's allowed upload MIME types without sanitizing the file contents or restricting the new types to administrators. An Author with the upload_files capability can use WordPress's normal /wp-admin/async-upload.php action=upload-attachment flow to store an SVG containing attacker-controlled script or an event handler. WordPress then serves the attachment from the public uploads directory as image/svg+xml with the payload intact, causing stored JavaScript to execute in the site's origin when a victim opens the attachment URL or encounters it in a rendering context. The exact plugin filter callback that extends upload_mimes is not disclosed by the CNA advisory. Version 2.7.0 is identified as fixed.

PublishedJul 30, 2026
Known safe version2.7.0
Published vulnerabilities for animation-addons-for-elementor
Safe version
Jul 30, 2026 CVE-2026-13330
Animation Addons lets authors upload executable SVG files
Animation Addons for Elementor before 2.7.0 unconditionally adds SVG and SVGZ to WordPress's allowed upload MIME types without sanitizing the file contents or restricting the new types to administrators. An Author with the upload_files capability can use WordPress's normal /wp-admin/async-upload.php action=upload-attachment flow to store an SVG containing attacker-controlled script or an event handler. WordPress then serves the attachment from the public uploads directory as image/svg+xml with the payload intact, causing stored JavaScript to execute in the site's origin when a victim opens the attachment URL or encounters it in a rendering context. The exact plugin filter callback that extends upload_mimes is not disclosed by the CNA advisory. Version 2.7.0 is identified as fixed.
2.7.0
CVE6.1
NVDPending
Jul 10, 2026 CVE-2026-15299
Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates: Cross-site scripting
Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.6.3. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.4
NVDPending
Jun 10, 2026 CVE-2025-8444
Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates: Cross-site scripting
Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.6.7. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.4
NVDPending
Apr 08, 2026 CVE-2026-39702
Animation Addons for Elementor: Cross-site scripting
Animation Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.6.1. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVDPending
Dec 09, 2025 CVE-2025-67540
Animation Addons for Elementor: A security weakness
Animation Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVDPending
Dec 18, 2024 CVE-2024-12340
Animation Addons for Elementor: Sensitive information exposure
Animation Addons for Elementor is affected by sensitive information exposure. Exploitation requires an authenticated contributor account. Successful exploitation can disclose data that should not be available to the caller. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.3
NVDPending