CVE-2026-13330: Unknown Animation Addons For Elementor

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with the upload_files capability (Author and above) to upload files containing malicious JavaScript, leading to Stored Cross-Site Scripting.

Affected products

  • Unknown Animation Addons For Elementor: before 2.7.0 (fixed in 2.7.0)

Published 2026-07-30. Last modified 2026-07-30.