The Music Player for Elementor plugin, used on WordPress, has a security issue that allows for Stored Cross-Site Scripting. This happens when the ‘album_buy_url’ parameter is not properly checked and any malicious code can be inserted. This can be done by someone who has Contributor-level access or higher, and the code will run whenever someone visits the affected page.