Junglewise Threat Intelligence

CVE-2026-8872: WordPress Animate Your Content Stored XSS in animation-set shortcode

CVE-2026-8872 · Severity: medium · CVSS 6.4 · Published 2026-05-27

Vendors: Wordpress.

Executive brief

The Animate Your Content plugin for WordPress, which allows users to add animations to website elements, contains a security flaw that allows authenticated users to inject malicious scripts. An attacker with contributor-level access or higher can use a specific shortcode to embed code that executes in the browsers of other visitors. This could lead to unauthorized actions being performed on behalf of site administrators or the theft of sensitive session information.

Technical details

The Animate Your Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'animation-set' shortcode in versions up to and including 1.0.0. The vulnerability exists within the shortcode_args_to_html_attrs() function, which fails to properly sanitize or escape user-supplied attributes before concatenating them into double-quoted HTML attributes. Specifically, the function does not utilize esc_attr(), allowing authenticated attackers with contributor-level permissions or higher to inject arbitrary web scripts. These scripts are stored on the server and execute in the context of any user who views the affected page.

Affected products

  • WordPress Animate Your Content Up to and including 1.0.0

Timeline

  • 2026-05-27: advisory: NVD publication date

References