The Essential Addons for Elementor plugin, which adds templates, widgets, and builders to WordPress, has a security flaw. This can allow hackers with at least contributor-level access to add harmful scripts to web pages using the ‘Fancy Text’, ‘Filter Gallery’, ‘Sticky Video’, ‘Content Ticker’, ‘Woo Product Gallery’, and ‘Twitter Feed’ widgets. This means that whenever a user visits one of these pages, the script could be activated.