Review
SlimStat
CVE published 2026-07-20
CVE-2026-12592
The SlimStat Analytics WordPress plugin before 5.5.0 has a cross-site scripting (XSS) vulnerability. An unauthenticated attacker can exploit this vulnerability by providing a malicious geolocation value, which will be executed in the browser of an administrator who views the analytics reports. The vulnerability requires the plugin to be configured to use the Cloudflare geolocation provider. This issue aff [truncated]