The Elementor Addon Elements plugin for WordPress is vulnerable to a security risk called Reflected Cross-Site Scripting. This means that in versions up to, and including 1.6.3, unauthenticated attackers can inject malicious web scripts into the administrative pages of a website. This can be done if they can get a site administrator to click on a link.