CVE-2026-12592
Deferred Deferred - Pending Action

Stored XSS in SlimStat Analytics WordPress Plugin

Vulnerability report for CVE-2026-12592, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: WPScan

Description

The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browser of an administrator who views the reports. Exploitation requires the SlimStat Analytics WordPress plugin before 5.5.0 to be configured to use the Cloudflare geolocation provider.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
slimstat analytics to 5.5.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in the SlimStat Analytics WordPress plugin versions below 5.5.0. It occurs because the plugin does not escape visitor-controlled geolocation data before displaying it in admin analytics reports. An attacker can exploit this by sending a malicious payload in the CF-IPCountry header, which gets stored and later executed when an administrator views certain reports.

Detection Guidance

Check if the SlimStat Analytics WordPress plugin version is below 5.5.0. Inspect HTTP headers for CF-IPCountry values containing suspicious payloads. Review admin analytics reports for unexpected JavaScript execution.

Impact Analysis

An attacker could steal session cookies or perform other malicious actions in the context of an administrator's browser session. This could lead to unauthorized access to the WordPress admin panel, data theft, or further compromise of the website.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. It could result in unauthorized data exposure, impacting user privacy and potentially leading to legal penalties.

Mitigation Strategies

Update the SlimStat Analytics plugin to version 5.5.0 or later. Disable Cloudflare geolocation provider if not required. Monitor admin reports for unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12592. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart