The plugin was vulnerable to Stored Cross-Site Scripting (XSS) in the “hotjar script” textarea. The request did include a CSRF nonce that was properly verified by the server and this vulnerability could only be exploited by administrator users.
Step 1: Install and activate the plugin “Hotjar Connecticator” Step 2: Now enter the following script on the “Hotjar script” text field. abc Step 3: Now we can see the script is stored and executed all the when we visit the website.