The Exclusive Addons for Elementor plugin for WordPress has a security issue that allows attackers to inject harmful code into pages using the Call To Action widget. This can happen on versions up to 2.6.9. It is possible for attackers with contributor-level access or higher to do this, and it can cause the code to run whenever a user visits the affected page.