Vulnerabilities
Vulnerable Software
Microsoft:  >> Clarity  >> 0.3  Security Vulnerabilities
The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.3. This is due to missing nonce validation on the edit_clarity_project_id() function. This makes it possible for unauthenticated attackers to change the project id and add malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVSS Score
6.1
EPSS Score
0.303
Published
2024-02-29
There is a Cross-Site Scripting vulnerability in Microsoft Clarity version 0.3. The XSS payload executes whenever the user changes the clarity configuration in Microsoft Clarity version 0.3. The payload is stored on the configuring project Id page.
CVSS Score
5.4
EPSS Score
0.006
Published
2021-11-19


Contact Us

Shodan ® - All rights reserved