What is CVE-2026-13330?
CVE-2026-13330 is a vulnerability in the Animation Addons for Elementor WordPress plugin before version 2.7.0. The plugin fails to sanitise uploaded SVG/SVGZ files, allowing users with Author-level permissions or higher to upload files containing malicious JavaScript, leading to a Stored Cross-Site Scripting (XSS) attack. Users should immediately update the plugin to version 2.7.0 or later.
Azərbaycanca: CVE-2026-13330, Animation Addons for Elementor WordPress plugin-in 2.7.0-dan əvvəlki versiyalarında aşkarlanmış boşluqdur. Plugin yüklənən SVG/SVGZ fayllarını sanitizə etmir, bu da "Author" və daha yüksək səlahiyyətli istifadəçilərə zərərli JavaScript ehtiva edən fayllar yükləməyə imkan verir və Stored Cross-Site Scripting (XSS) hücumuna səbəb olur. Plugin-i dərhal 2.7.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which version of the Animation Addons for Elementor plugin is affected by CVE-2026-13330?
CVE-2026-13330 exists in the Animation Addons for Elementor WordPress plugin before version 2.7.0.
What level of user permissions is required to exploit CVE-2026-13330?
Exploiting this vulnerability requires 'Author' or higher-level user permissions on the WordPress site.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.