CVE-2021-24259
Addon Elements for Elementor prior to version 1.11.2 contains stored cross-site scripting vulnerabilities in multiple widgets that can be exploited by users with contributor-level permissions. The Flip Box widget's "front_title_html_tag" and "back_title_html_tag" parameters accept arbitrary JavaScript code instead of restricting input to legitimate HTML tags, as does the Price Table widget through its "heading_tag" and "sub_heading_tag" parameters. The Split Text, Text Separator, and Timeline widgets are similarly vulnerable through their respective tag and parameter fields. When affected pages are viewed or previewed, the injected malicious scripts execute in the browser.
Based on public CVE data (MITRE/NVD).