The Exclusive Addons for Elementor plugin for WordPress has a security issue that allows for Stored Cross-Site Scripting. This means that hackers can inject harmful code into pages and have it run whenever someone accesses that page. This affects all versions of the plugin up to 2.7.9.4 and can be exploited by attackers with Contributor-level access or higher.