Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39702

24
FAUCET Score

CVE-2026-39702 is a DOM-based cross-site scripting (XSS) vulnerability in the Wealcoder Animation Addons for Elementor plugin, affecting versions up to and including 2.6.1. The vulnerability stems from improper neutralization of user input during web page generation, allowing attackers to inject malicious scripts. This flaw impacts WordPress sites utilizing this animation plugin, which is commonly used for dynamic content creation within the Elementor page builder. The vulnerability carries a CVSS score of 6.5 (medium severity) and requires network access with low attack complexity, though it does necessitate user privileges and interaction. An authenticated attacker can exploit this weakness to execute arbitrary JavaScript in victims' browsers within the context of the affected site, potentially leading to unauthorized data access, modification, or minor system disruption. The broader impact extends across site functionality due to the changed scope parameter in the CVSS vector. There is currently no evidence of active exploitation in the wild, and the vulnerability does not appear on threat intelligence watch lists. The EPSS score of 0.00034 indicates minimal likelihood of near-term exploitation compared to other disclosed vulnerabilities. Community attention remains low, suggesting this issue has not yet garnered significant security researcher focus, though organizations using this plugin should still prioritize patching to versions beyond 2.6.1.

Impacted Technologies

VendorProductVersion(s)CPE
WealcoderAnimation Addons For Elementor
>= 0, <= 2.6.1CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
2.3
Impact Score
3.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.13%
Probability of exploitation in next 30 days
EPSS Percentile
3.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0013 is in the 1st percentile among its peer group of 15,239 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

patchstack.com / database/Wordpress/Plugin/animation-addons-for-elementor/vulnerability/wordpress-animation-addons-for-elementor-plugin-2-6-1-cross-site-scripting-xss-vulnerability