Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 20 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Mon, 20 Jul 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browser of an administrator who views the reports. Exploitation requires the SlimStat Analytics WordPress plugin before 5.5.0 to be configured to use the Cloudflare geolocation provider. | |
| Title | SlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry Header | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-20T13:14:45.585Z
Reserved: 2026-06-18T09:19:56.429Z
Link: CVE-2026-12592
Updated: 2026-07-20T13:14:34.533Z
No data.
No data.
OpenCVE Enrichment
No data.