The Essential Addons for Elementor plugin for WordPress has a vulnerability that allows attackers to inject harmful web scripts into pages using the ‘Dual Color Header’, ‘Event Calendar’, and ‘Advanced Data Table’ widgets. This can happen on any version up to 5.9.19, and even if the attacker only has contributor-level access. This means that when a user visits the affected page, the harmful script will be executed.