CVE-2026-13330
Received Received - Intake

Stored XSS via Malicious SVG Upload in Animation Addons for Elementor

Vulnerability report for CVE-2026-13330, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: WPScan

Description

The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with the upload_files capability (Author and above) to upload files containing malicious JavaScript, leading to Stored Cross-Site Scripting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-30
AI Q&A
2026-07-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
animation_addons elementor to 2.7.0 (exc)
animation_addons animation_addons_for_elementor to 2.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the Animation Addons for Elementor WordPress plugin before version 2.7.0. The plugin allows users with upload capabilities to upload SVG or SVGZ files without proper sanitization, enabling malicious JavaScript execution when the files are accessed.

Detection Guidance

Check if the Animation Addons for Elementor plugin version is below 2.7.0. Inspect uploaded SVG/SVGZ files for malicious JavaScript payloads. Review WordPress upload permissions and allowed file types.

Impact Analysis

Attackers with Author-level access or higher can upload malicious SVG files containing JavaScript. When these files are accessed, the embedded script executes, potentially stealing session cookies, redirecting users, or performing actions on their behalf. This could lead to account takeovers or unauthorized data access.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Organizations may face compliance penalties if user data is compromised through this exploit.

Mitigation Strategies

Update the Animation Addons for Elementor plugin to version 2.7.0 or later. Remove SVG/SVGZ from allowed upload types if not required. Restrict upload permissions to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13330. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart