Impact
The SlimStat Analytics WordPress plugin contains a flaw that fails to properly escape geolocation input taken from the CF‑IPCountry header. An unauthenticated user can craft a malicious payload that is stored in the plugin’s analytics report and later executed when an administrator views the page. The attack hijacks the administrator’s browser session, allowing for credential theft, session hijack or injection of arbitrary scripts. This vulnerability follows the Cross‑Site Scripting weakness identified as CWE‑79.
Affected Systems
Any WordPress site that has the SlimStat Analytics plugin of a version earlier than 5.5.0 configured to use the Cloudflare geolocation provider. The plugin is broadly available through WordPress repositories and may be installed on a wide range of public or private sites. No version or build numbers beyond the major 5.5.0 threshold are affected when the geolocation provider is enabled.
Risk and Exploitability
The CVSS score of 7.5 reflects the high impact of a stored XSS in an admin context. The EPSS score of less than 1% indicates a low probability of widespread exploitation at present, and the vulnerability is not yet listed in the CISA KEV catalog. An attacker requires only unauthenticated access to the site and the ability to set the CF‑IPCountry header in a request; once the payload is stored, any administrator who views the analytics report will have the script executed. Therefore, while the exploitation difficulty is low, the potential damage to administrative accounts is high.
OpenCVE Enrichment