VYPR

Slimstat

by WordPress

CVEs (1)

  • CVE-2026-12592Jul 20, 2026
    risk 0.00cvss epss 0.00

    The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browser of an…