DOM-Based Stored Cross-Site Scripting in Animation Addons for Elementor by WordPress
CVE-2025-8444
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 June 2026
What is CVE-2025-8444?
The Animation Addons for Elementor plugin, designed for WordPress, contains a vulnerability that allows for DOM-Based Stored Cross-Site Scripting due to insufficient input sanitization and output escaping in multiple parameters. Users with Contributor-level access and above can exploit this flaw to inject harmful web scripts into pages which execute upon user access. This poses a significant security risk for websites utilizing this plugin.
Affected Version(s)
Animation Addons for Elementor β GSAP Motion Elementor Addons & Website Templates 0 <= 2.6.7