Junglewise Threat Intelligence

CVE-2025-8444: WPCodingDev Animation Addons for Elementor DOM-based stored XSS

CVE-2025-8444 · Severity: medium · CVSS 6.4 · Published 2026-06-10

Executive brief

A vulnerability exists in a popular WordPress plugin used for adding animations and templates to websites. An attacker with basic contributor-level access can inject malicious scripts into website pages. When other users or administrators visit these pages, the scripts execute in their browsers, potentially leading to unauthorized actions or data theft.

Technical details

The Animation Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on multiple parameters. The flaw resides in the client-side JavaScript processing (specifically within assets/js/wcf-addons.min.js). An authenticated attacker with Contributor-level permissions or higher can exploit this by injecting arbitrary web scripts into page metadata or settings. Because the payload is stored and then executed within the Document Object Model (DOM) context of any user viewing the page, it can be used to hijack sessions or perform actions on behalf of administrators. The vulnerability is present in all versions up to and including 2.6.7.

Affected products

  • WPCodingDev Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates Up to, and including, 2.6.7

Timeline

  • 2026-06-10: disclosed: NVD publication date

References