Executive brief
The Animation Addons for Elementor plugin for WordPress, which provides visual effects for website builders, contains a security flaw in its Weather widget. An attacker with basic contributor-level access can inject malicious scripts into the website's pages. When other users or visitors view the affected page, these scripts can execute, potentially leading to unauthorized actions or data theft.
Technical details
The Animation Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient output escaping in the Weather widget's render() function. Specifically, the 'weather_style' and 'move_direction' parameters are placed into an HTML class attribute without using the esc_attr() function. Because Elementor does not perform server-side validation of SELECT control values, an authenticated attacker with Contributor-level permissions can use a crafted AJAX request to store malicious scripts in the post metadata. These scripts execute in the browser of any user visiting the affected page, provided an OpenWeatherMap API key is configured. The issue is fixed in version 2.6.4.
Affected products
- wealcoder Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates up to, and including, 2.6.3
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory
References
- https://plugins.trac.wordpress.org/browser/animation-addons-for-elementor/tags/2.6.3/widgets/weather.php
- https://plugins.trac.wordpress.org/browser/animation-addons-for-elementor/tags/2.6.4/widgets/weather.php
- https://plugins.trac.wordpress.org/changeset?old_path=/animation-addons-for-elementor/tags/2.6.3&new_path=/animation-addons-for-elementor/tags/2.6.4
- https://www.wordfence.com/threat-intel/vulnerabilities/id/e2e755c7-7d1e-45f7-9d0b-2df1ef0bdd02?source=cve