The Exclusive Addons for Elementor plugin for WordPress has a security issue that can allow hackers to inject harmful scripts into web pages. This can happen through the Team Member widget and affects all versions up to 2.6.9.6. This vulnerability is caused by the plugin not properly filtering and protecting the ‘url’ attribute provided by users. It can only be exploited by users with contributor-level access or higher.