CVE-2026-12592 PUBLISHED

SlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry Header

Assigner: WPScan
Reserved: 18.06.2026 Published: 20.07.2026 Updated: 20.07.2026

The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browser of an administrator who views the reports. Exploitation requires the SlimStat Analytics WordPress plugin before 5.5.0 to be configured to use the Cloudflare geolocation provider.

Product Status

Vendor Unknown
Product SlimStat Analytics
Versions Default: unaffected
  • affected from 0 to 5.5.0 (excl.)

Credits

  • Yaswanth Reddy Sunkara finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE