WordPress Plugin Vulnerabilities

Animation Addons for Elementor < 2.7.0 - Author+ Stored XSS via SVG Upload

Description

The plugin does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with the upload_files capability (Author and above) to upload files containing malicious JavaScript, leading to Stored Cross-Site Scripting.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Vaibhav Narkhede
Submitter
Vaibhav Narkhede
Verified
Yes

Timeline

Publicly Published
2026-07-13 (about 1 month ago)
Added
2026-07-13 (about 1 month ago)
Last Updated
2026-07-13 (about 1 month ago)

Other