CVE-2026-39702 is a DOM-based cross-site scripting (XSS) vulnerability in the Wealcoder Animation Addons for Elementor plugin, affecting versions up to and including 2.6.1. The vulnerability stems from improper neutralization of user input during web page generation, allowing attackers to inject malicious scripts. This flaw impacts WordPress sites utilizing this animation plugin, which is commonly used for dynamic content creation within the Elementor page builder. The vulnerability carries a CVSS score of 6.5 (medium severity) and requires network access with low attack complexity, though it does necessitate user privileges and interaction. An authenticated attacker can exploit this weakness to execute arbitrary JavaScript in victims' browsers within the context of the affected site, potentially leading to unauthorized data access, modification, or minor system disruption. The broader impact extends across site functionality due to the changed scope parameter in the CVSS vector. There is currently no evidence of active exploitation in the wild, and the vulnerability does not appear on threat intelligence watch lists. The EPSS score of 0.00034 indicates minimal likelihood of near-term exploitation compared to other disclosed vulnerabilities. Community attention remains low, suggesting this issue has not yet garnered significant security researcher focus, though organizations using this plugin should still prioritize patching to versions beyond 2.6.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Wealcoder | Animation Addons For Elementor | >= 0, <= 2.6.1CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.