Animate It!
Animate It! has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2019 and 2022; all 4 are fixed as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2019 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (75%). Other recurring categories include Cross-Site Request Forgery (CSRF).
Every one of the 4 issues recorded for Animate It! has a vendor fix available, so running the current release closes all known holes.
Animate It! is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2019-17386Animate It <= 2.3.5 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Animate It!
Author
eleopard
Add cool CSS3 animations to your content. Demo | Documentation | Class Generator Some of the Key features Include: Allowing user to apply CSS3 animations on Post, Widget and Pages. 50+ Entry, Exit and Attention Seeker Animations. Capability to apply animation on Scroll. Capability to add different scroll offset on individual animation blocks. Capability to apply animation on Click. Capability to apply animation on Hover. Providing delay feature in animation to create a nice animation sequence. Providing feature to control the duration for a more precise animation. Providing a button in the editor to easily add an animation block in the article or post. Allow user to add animation on WordPress widgets. Use Class Generator to generate the required animation classes. Allow user to apply animation infinitely or any fixed number of times. Option to add custom CSS classes to individual animation block. Options to enable or disable animations on Smartphones and Tablets. Spanish and German language support. Thanks to Santiago Marrone, Christian Herrmann Custom Animate It! block to apply animations on other Gutenberg blocks. All the CSS3 animations are from Animate.css and Animo.js
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C