The plugin was vulnerable to Stored Cross-Site Scripting (XSS) in the “hotjar script” textarea. The request did include a CSRF nonce that was properly verified by the server and this vulnerability could only be exploited by administrator users.
Step 1: Install and activate the plugin "Hotjar Connecticator"
Step 2: Now enter the following script on the "Hotjar script" text field.
abc</textarea><script>alert(xss)</script>
Step 3: Now we can see the script is stored and executed all the when we visit the website.