Impact
The SlimStat Analytics plugin for WordPress is vulnerable to stored XSS through the notes and resource parameters. Insufficient input sanitization and output escaping allow an unauthenticated attacker to embed arbitrary JavaScript in the plugin’s data. The injected code is persisted and executed whenever an administrator opens the Recent Custom Events report, potentially compromising the session by delivering client‑side malicious scripts.
Affected Systems
Veron Labs SlimStat Analytics, all releases up to and including version 5.3.4.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, while the EPSS score of < 1% suggests a low to moderate likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the flaw by sending unauthenticated HTTP requests to the vulnerable endpoints; no authentication or privileged access is required for injection.
OpenCVE Enrichment