The Royal Elementor Addons and Templates plugin for WordPress has a security issue that could allow attackers to inject harmful code into web pages. This can happen through the Logo Widget feature, and affects all versions up to 1.3.91. This vulnerability is caused by a lack of proper protection for user-provided URLs. As a result, attackers with contributor-level or higher permissions could potentially execute malicious scripts on web pages.