The Royal Elementor Addons and Templates plugin for WordPress has a security vulnerability that allows for Stored Cross-Site Scripting. This means that malicious code can be inserted into pages using the Form Builder widget. This vulnerability affects all versions up to and including 1.3.974. It is possible for attackers who have contributor-level access or higher to inject harmful web scripts into pages, which will then run whenever a user visits the page.