WordPress Elementor Website Builder plugin before 3.1.4 contains a DOM cross-site scripting vulnerability. It does not sanitize or escape user input appended to the DOM via a malicious hash.
View the template here CVE-2021-24891.yaml
References:
https://wpscan.com/vulnerability/fbed0daa-007d-4f91-8d87-4bca7781de2d