Back to overview

CVE-2026-12592

HIGH Exploitation: PoC
7.5
CVSS 3.1
Description
The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browser of an administrator who views the reports. Exploitation requires the SlimStat Analytics WordPress plugin before 5.5.0 to be configured to use the Cloudflare geolocation provider.

Metadata

CVE ID
CVE-2026-12592
State
PUBLISHED
Assigner
WPScan
Reserved
2026-06-18 09:19 UTC
Published
2026-07-20 06:00 UTC
Last updated
2026-07-20 13:14 UTC
Primary CWE
CWE-79
CWE-79 Improper Neutralization of Input During Web Page Gene…
Vendor / Product
Unknown / SlimStat Analytics
Sources
cve.org  ·  NVD

Severity & Metrics

7.5 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Unknown SlimStat Analytics 0 < 5.5.0
Weakness (CWE)
CWESourceDescription
cna CWE-79 Cross-Site Scripting (XSS)
CWE-79 adp CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.5 HIGH 3.1 adp CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Back to overview