Home/Product/wp slimstat analytics
Product

wp slimstat analytics

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-9548
< 5.2.7
The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all version
7.2HIGH
CVE-2024-1073
<= 5.1.3
The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filter_array' parameter in all v
6.4MEDIUM
CVE-2022-45373
< 5.0.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jason Crouse, VeronaLabs Sli
8.8HIGH
CVE-2023-4598
< 5.0.10
The Slimstat Analytics plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and inclu
8.8HIGH
CVE-2023-40676
<= 5.0.8
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics plugin <= 5.0.8 ver
5.9MEDIUM
CVE-2023-4597
<= 5.0.9
The Slimstat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slimstat' shortcode in versions
6.4MEDIUM
CVE-2022-45366
<= 5.0.4
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics plugin <= 5.0.4 version
7.1HIGH
CVE-2023-0630
< 4.9.3.3
The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that concatenates at
8.8HIGH
CVE-2022-4310
< 4.9.3
The Slimstat Analytics WordPress plugin before 4.9.3 does not sanitise and escape the URI when logging requests, which could allow
6.1MEDIUM
CVE-2019-15112
< 4.8.1
The wp-slimstat plugin before 4.8.1 for WordPress has XSS.
6.1MEDIUM
CVE-2015-9273
< 4.1.6.1
The wp-slimstat (aka Slimstat Analytics) plugin before 4.1.6.1 for WordPress has XSS via an HTTP Referer header, or via a field as
6.1MEDIUM
threatengine.sh