CVE-2026-94154: Aurora Heatmap <= 1.7.2 - Unauthenticated Stored Cross-Site Scripting via 'url' Parameter
The Aurora Heatmap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an admin user clicks the injected heatmap link.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
WordPress sites using Aurora Heatmap version 1.7.2 or earlier are affected. An attacker does not need authentication to submit the malicious input.
What user interaction is required for the injected script to run?
The injected script executes when an administrator clicks the attacker-injected heatmap link. The vulnerability does not state that merely viewing a page triggers execution.
What is the likely impact if exploitation succeeds?
The issue can expose or modify information in the administrator's browser context through arbitrary script execution. The supplied vector indicates low confidentiality and integrity impact, with no availability impact.