The Exclusive Addons Elementor plugin for WordPress has a security issue that allows unauthorized people to access sensitive data. This is because the plugin does not properly check user permissions when using the duplicate_post() function in versions up to 2.6.9.1. This means that attackers who have contributor-level access or higher can duplicate posts from other users, potentially exposing private information.