CVE-2026-13330

Animation Addons for Elementor < 2.7.0 - Author+ Stored XSS via SVG Upload

The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with the upload_files capability (Author and above) to upload files containing malicious JavaScript, leading to Stored Cross-Site Scripting.


We have discovered 892 live websites that are affected by CVE-2026-13330.

Run a Free Instant Scan




Affected Software

Product  Animation Addons for Elementor
Category Wordpress Plugins
Vulnerable Domains892 live websites (99% of Animation Addons for Elementor install base)
Vulnerable Versions
  • from 0 through 2.7
Vulnerable Versions Count23 versions ( 96% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 30, 2026
  • Updated - Jul 30, 2026

Credits

  • Vaibhav Narkhede (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-13330
United States232 websites



Germany93 websites
India78 websites
GB52 websites
Italy52 websites
France47 websites
Cyprus37 websites
Australia21 websites
Canada19 websites
Netherlands17 websites

Website Distribution by TLD

Number of websites using CVE-2026-13330
.com447 websites
.de40 websites
.it40 websites
.org27 websites
.co.uk17 websites
.com.br16 websites
.com.au15 websites
.net14 websites
.nl14 websites
.fr14 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-13330

Top websites that are affected by CVE-2026-13330. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States***,***
****.eu Belgium***,***
*******.com United States***,***
*********.com India***,***
********.org India***,***
********.biz Germany***,***
***********.org United States***,***
*******************.com Germany***,***
*********.cz Czech Republic***,***
************.cz Czech Republic***,***
See full domain list

FAQ

CVE-2026-13330 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Animation Addons for Elementor
A total of 892 websites have been identified as vulnerable to CVE-2026-13330, based on global website indexing conducted by WebTechSurvey.
The Animation Addons for Elementor is affected by the CVE-2026-13330 vulnerability.
Animation Addons for Elementor versions up to 2.7 are vulnerable to CVE-2026-13330.
CVE-2026-13330 is resolved in version 2.7 of Animation Addons for Elementor.