Impact
The SlimStat Analytics plugin for WordPress is vulnerable to time‑based SQL injection via the ‘args’ parameter. The flaw exists because the value is insufficiently escaped and the SQL query is not prepared, allowing an attacker to append arbitrary SQL. Because this is limited to authenticated users with Subscriber or higher privileges, the attacker can extract confidential information from the database but cannot compromise the host directly.
Affected Systems
The vulnerability affects versions up to and including 5.3.1 of SlimStat Analytics by veronalabs. No other versions or products are currently listed as affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity flaw, and the EPSS score of less than 1% suggests a low likelihood of exploitation under current conditions. The issue is not listed in the CISA KEV catalog. An attacker must first authenticate with at least Subscriber-level access; there is no known public exploitation, but the low probability does not eliminate the need to remediate.
OpenCVE Enrichment