The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browser of an administrator who views the reports. Exploitation requires the SlimStat Analytics WordPress plugin before 5.5.0 to be configured to use the Cloudflare geolocation provider.
Metrics
Affected Vendors & Products
References
History
Mon, 20 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Mon, 20 Jul 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browser of an administrator who views the reports. Exploitation requires the SlimStat Analytics WordPress plugin before 5.5.0 to be configured to use the Cloudflare geolocation provider. | |
| Title | SlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry Header | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-20T13:14:45.585Z
Reserved: 2026-06-18T09:19:56.429Z
Link: CVE-2026-12592
Updated: 2026-07-20T13:14:34.533Z
No data.
No data.
OpenCVE Enrichment
No data.