Security Advisory

CVE-2021-24301

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-05-24 10:58:04
Last updated 2024-08-03 19:28:23
Assigner WPScan
State PUBLISHED

Description

The Hotjar Connecticator WordPress plugin through 1.1.1 is vulnerable to Stored Cross-Site Scripting (XSS) in the hotjar script textarea. The request did include a CSRF nonce that was properly verified by the server and this vulnerability could only be exploited by administrator users.