The Visibility Logic for Elementor plugin for WordPress is vulnerable to security risks in versions up to and including 2.3.4. This is due to the missing or incorrect validation of an additional security measure known as a Nonce on the toggle_option function. This means that it is possible for unauthenticated attackers to change the plugin settings by tricking a site administrator into clicking on a link.