Stored Cross-Site Scripting in Animate Your Content Plugin for WordPress
CVE-2026-8872
6.4MEDIUM
What is CVE-2026-8872?
The Animate Your Content plugin for WordPress has a vulnerability that allows authenticated users with contributor-level access or higher to execute arbitrary scripts on web pages. This occurs through the plugin's 'animation-set' shortcode, where user input is inadequately sanitized and improperly integrated into HTML attributes. Attackers can leverage this flaw to inject malicious scripts that run when other users visit compromised pages, posing a significant threat to site integrity and user safety.
Affected Version(s)
Animate Your Content 0 <= 1.0.0