Typing Effect
Typing Effect has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.
2 independent researchers contributed these findings, one record each. Typing Effect is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.3.10.
CVE-2026-66644Typing Effect <= 1.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Typing Effect
Author
93digital
This plugin is no longer be supported from v1.3.6. Typing Effect allows you to generate a shortcode that will ‘type out’ words on to a page or post, in a widget or directly in a theme or template file. The plugin is based on the Typed.js typing animation script by Matt Boldt. Simply add your words or sentences, click ‘Generate Shortcode’ and copy and paste the shortcode into a page, post or text widget. You can also configure settings such as how quickly the typing effect takes place, delays before starting or backspacing, set the animation to loop repeatedly or randomise the order your words or sentences are typed out and deleted. To view a demo of the original animation click here
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C