SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-13330

MEDIUM · CVSS 6.1 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Animation Addons for Elementor WordPress plugin prior to version 2.7.0 is vulnerable due to inadequate sanitization of uploaded SVG/SVGZ files, enabling users with upload permissions to introduce malicious JavaScript. This flaw can result in Stored Cross-Site Scripting (XSS), potentially compromising site security and user data. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-13330
Severity
MEDIUM
CVSS
6.1
EPSS
0.18%
WordPress Java

Original NVD Description

The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with the upload_files capability (Author and above) to upload files containing malicious JavaScript, leading to Stored Cross-Site Scripting.