Input validation vulnerability in Hotjar 1.0.15

The Hotjar plugin for WordPress, up to and including version 1.0.15, has a security vulnerability that could allow attackers with administrator-level permissions or higher to inject malicious scripts into webpages. These malicious scripts would be executed when someone visits the webpage containing the malicious code. This only affects WordPress websites with multiple sites or websites where a certain security setting has been disabled.

Detected in:

Hotjar fixed vulnerable versions: >= * <= 1.0.15

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.