The Exclusive Addons for Elementor plugin for WordPress has a security vulnerability that allows attackers to inject harmful web scripts into a website. This can happen through the ‘Link To’ url in carousels. This vulnerability affects all versions of the plugin up to 2.6.8 and can only be exploited by authenticated attackers with contributor-level or higher permissions.