Junglewise Threat Intelligence

CVE-2026-39702: Wealcoder Animation Addons for Elementor DOM-based XSS

CVE-2026-39702 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Executive brief

Animation Addons for Elementor is a WordPress plugin used to add visual effects and animations to websites. A security vulnerability in this plugin allows an attacker with basic contributor access to inject malicious scripts into web pages. If a site visitor or administrator views these pages, the scripts could redirect them to malicious sites, display unauthorized advertisements, or compromise their session.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Wealcoder Animation Addons for Elementor plugin due to improper neutralization of user-supplied input during web page generation. The flaw allows an authenticated attacker with 'Contributor' level permissions or higher to inject malicious JavaScript payloads that execute in the context of a victim's browser. Successful exploitation requires a privileged user to interact with a crafted page or link. While the NVD entry lists versions up to 2.6.1 as affected, the primary source (Patchstack) indicates the vulnerability persists through version 2.7.1 with no official patch currently available.

Affected products

  • Wealcoder Animation Addons for Elementor <= 2.7.1

Timeline

  • 2026-01-30: other: Vulnerability reported by researcher Abu Hurayra
  • 2026-03-01: advisory: Initial advisory published by Patchstack
  • 2026-04-08: disclosed: CVE published to NVD

References