The Elementor Addon Elements plugin for WordPress has an issue in versions up to and including 1.12.7. This issue makes it possible for attackers to make changes to the plugin’s settings without being authenticated. This could happen if the attacker is able to convince a site administrator to click on a link. To fix this issue, an update is needed to make sure that nonce validation is in place.