The Essential Addons for Elementor plugin for WordPress has a vulnerability that allows attackers to inject harmful web scripts into pages. This can happen through the plugin’s Fancy Text widget, which does not properly clean up user-inputted attributes. As a result, anyone with contributor-level access or higher can potentially execute these injected scripts when a user visits the affected page.