What the vulnerability does
01Description
The Animation Addons for Elementor Pro plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_elementor_plugin_handler() function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins which can be leveraged to further infect a victim when Elementor is not activated on a vulnerable site.
Explanation of Vulnerability in Simple Terms
02Summary
Animation Addons for Elementor Pro versions 1.6 and earlier lack proper authorization checks, allowing authenticated users with low privileges to perform actions restricted to higher-privilege roles. An attacker with a basic user account can read, modify, or delete sensitive data and settings. Update to a version newer than 1.6 immediately.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete data and settings that should be restricted to administrators or higher-privilege users.
Potential impact on your site
04Site Impact
Any registered user can access and alter plugin settings, animations, and potentially site content without authorization.
Conditions required to exploit
05Prerequisites
Attacker needs a low-privilege user account on the site; no special user interaction required.
Key dates
06Disclosure timeline
March 4, 2025
CVE published
April 8, 2026
Record updated