WP Slimstat is a WordPress analytics plugin with a narrowly scoped product portfolio but notable presence in the analytics-plugin segment of WordPress deployments. Its vulnerability disclosures center on the Slimstat Analytics product and reflect input-handling and data-processing patterns typical of web-facing logging and reporting tools. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wp Slimstat over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0630HIGH The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that concatenates attributes directly into an SQL query. | Mar 20, 2023 | 8.8 | 33 | NO | YES |
CVE-2022-45373CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics allows SQL Injection.This issue af | Nov 6, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-4310MEDIUM The Slimstat Analytics WordPress plugin before 4.9.3 does not sanitise and escape the URI when logging requests, which could allow unauthenticated attackers to perform Stored Cross | Jan 9, 2023 | 6.1 | 21 | NO | NO |
CVE-2019-15112MEDIUM The wp-slimstat plugin before 4.8.1 for WordPress has XSS. | Aug 21, 2019 | 6.1 | 21 | NO | NO |
CVE-2023-4597MEDIUM The Slimstat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slimstat' shortcode in versions up to, and including, 5.0.9 due to insufficient in | Aug 30, 2023 | 6.4 | 20 | NO | NO |
CVE-2022-45366MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics plugin <= 5.0.4 versions. | May 25, 2023 | 6.1 | 20 | NO | NO |
CVE-2024-9548MEDIUM The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due to insufficient | Oct 15, 2024 | 6.1 | 19 | NO | NO |
CVE-2023-4598MEDIUM The Slimstat Analytics plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 5.0.9 due to insufficient escaping on the us | Oct 20, 2023 | 6.5 | 19 | NO | NO |
CVE-2024-1073MEDIUM The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filter_array' parameter in all versions up to, and including, 5.1.3 due to insuffi | Feb 2, 2024 | 5.4 | 18 | NO | NO |
CVE-2015-9273MEDIUM The wp-slimstat (aka Slimstat Analytics) plugin before 4.1.6.1 for WordPress has XSS via an HTTP Referer header, or via a field associated with JavaScript-based Referer tracking. | Oct 7, 2018 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wp Slimstat.
Media articles that mention a CVE ID that affects a product developed by Wp Slimstat — matched by CVE ID, not by vendor name.