A plugin called “Exclusive Addons for Elementor” on WordPress has a security issue where attackers can insert harmful code into a website through a button widget. This can happen in any version up to 2.6.9.3 because the plugin does not properly filter out or protect against this type of attack. People with contributor access or higher can exploit this vulnerability to potentially harm users who visit the affected pages.