Inspectlet – AI-Powered Session Replay, Heatmaps & Analytics
Inspectlet – AI-Powered Session Replay, Heatmaps & Analytics has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Inspectlet – AI-Powered Session Replay, Heatmaps & Analytics has a vendor fix available, so running the current release closes it.
All of these findings were reported by Nabil Irawan. Inspectlet – AI-Powered Session Replay, Heatmaps & Analytics is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2025-49048Inspectlet - User Session Recording and Heatmaps <= 2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Inspectlet – AI-Powered Session Replay, Heatmaps & Analytics
Author
inspectlet
Inspectlet records real user sessions on your website and uses AI to surface what matters — rage clicks, errors, drop-offs, and the moments worth watching. Stop guessing what your users want. AI-Powered AI Session Insights — AI watches every session and surfaces the ones that matter. Rage clicks, errors, form abandonment, and conversion drop-offs are detected automatically. Ask Inspectlet AI — ask questions about your users in plain English and get instant answers backed by your analytics data. Core Analytics Session Replay — watch real visitors click, scroll, type, and navigate your site Dynamic Heatmaps — eye-tracking, click, and scroll heatmaps that work on dynamic content Form Analytics — find where users abandon your forms and which fields cause friction Testing & Feedback A/B Testing — test designs with a visual editor, goal tracking, and statistical significance Feedback Surveys — collect NPS and on-site feedback at the right moment Error Logging — catch JavaScript errors automatically with stack traces and session replay links Setup takes 30 seconds: Install and activate the plugin. Go to Settings → Inspectlet. Enter your Website ID (found in your Inspectlet dashboard under “Install Tracking Code”). Save — done!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C