The Happy Addons plugin for Elementor on WordPress is at risk for a type of cyber attack called Stored Cross-Site Scripting. This is because the plugin does not properly clean up or protect against dangerous code that could be inserted into the ‘_id’ section. This means that someone with Contributor-level access or higher could potentially add harmful code to a page that will run whenever someone views that page.