CVE Published: 24/05/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: WPScan |
Vendor: Blue Medicine Labs |
Product: Hotjar Connecticator Status : PUBLISHED
CVE-2021-24301 Description
The Hotjar Connecticator WordPress plugin through 1.1.1 is vulnerable to Stored Cross-Site Scripting (XSS) in the \'hotjar script\' textarea. The request did include a CSRF nonce that was properly verified by the server and this vulnerability could only be exploited by administrator users.