SlimStat Analytics
cpe:2.3:a:wp-slimstat:slimstat_analytics:*:*:*:*:wordpress:*:*
- < 5.5.0
A stored cross-site scripting vulnerability has been identified in the SlimStat Analytics WordPress plugin, affecting versions prior to 5.5.0. The issue arises because the plugin fails to properly escape geolocation values controlled by visitors before displaying them in admin analytics reports. This flaw allows unauthenticated visitors to inject a cross-site scripting payload that is executed in the browser of an administrator viewing the reports. Exploitation requires the plugin to be set up with the Cloudflare geolocation provider.
Exploitation of this vulnerability allows for unauthenticated stored cross-site scripting, where injected scripts are executed in the context of an administrator's browser session.
To reproduce this vulnerability, first ensure that the SlimStat Analytics WordPress plugin is active and configured to use the Cloudflare geolocation provider. As an unauthenticated visitor, send a tracked hit to the WordPress site using the Cloudflare geolocation headers. Include a payload in the 'CF-IPCountry' header, which will be stored in the 'wp_slim_stats' table. Once the payload is injected, an administrator can view the SlimStat Audience dashboard or the Access Log report, where the stored payload will be executed as JavaScript in the administrator's browser.
Users are advised to update the SlimStat Analytics WordPress plugin to version 5.5.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.