The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with the upload_files capability (Author and above) to upload files containing malicious JavaScript, leading to Stored Cross-Site Scripting.
We have discovered 892 live websites that are affected by CVE-2026-13330.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 892 live websites (99% of Animation Addons for Elementor install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 23 versions ( 96% of all versions) |
| 232 websites | |
| 93 websites | |
| 78 websites | |
| 52 websites | |
| 52 websites | |
| 47 websites | |
| 37 websites | |
| 21 websites | |
| 19 websites | |
| 17 websites |
| .com | 447 websites |
| .de | 40 websites |
| .it | 40 websites |
| .org | 27 websites |
| .co.uk | 17 websites |
| .com.br | 16 websites |
| .com.au | 15 websites |
| .net | 14 websites |
| .nl | 14 websites |
| .fr | 14 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | ***,*** | ||
| ****.eu | ***,*** | ||
| *******.com | ***,*** | ||
| *********.com | ***,*** | ||
| ********.org | ***,*** | ||
| ********.biz | ***,*** | ||
| ***********.org | ***,*** | ||
| *******************.com | ***,*** | ||
| *********.cz | ***,*** | ||
| ************.cz | ***,*** |
FAQ