Lucene search

K

Hotjar Security Vulnerabilities

cve
cve

CVE-2023-1259

The Hotjar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the hotjar_site_id in versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and...

5.5CVSS

5.3AI Score

0.0004EPSS

2023-10-14 12:15 PM
28
cve
cve

CVE-2021-24301

The Hotjar Connecticator WordPress plugin through 1.1.1 is vulnerable to Stored Cross-Site Scripting (XSS) in the 'hotjar script' textarea. The request did include a CSRF nonce that was properly verified by the server and this vulnerability could only be exploited by administrator...

5.4CVSS

5.2AI Score

0.001EPSS

2021-05-24 11:15 AM
27
4