The plugin called Royal Elementor Addons and Templates for WordPress has a security issue called Cross-Site Request Forgery. This means that anyone can add items to a user’s wishlist without being authenticated if they can trick the site administrator into clicking on a link. This vulnerability exists in all versions up to 1.3.87.