The Happy Addons for Elementor plugin for WordPress has a security vulnerability that allows hackers to insert harmful code into the plugin’s Calendy widget. This can happen in all versions up to and including 3.10.4 because the plugin does not properly clean and protect user input. This means that attackers with contributor-level access or higher can add malicious code to pages that will run when a user views the page.