SlimStat Analytics Plugin Vulnerable to Stored Cross-Site Scripting
CVE-2024-9548
What is CVE-2024-9548?
The SlimStat Analytics plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability through the resource parameter. This issue arises from inadequate sanitization of input and improper output escaping during the logging of visitor requests, affecting all versions up to and including 5.2.6. As a result, unauthenticated attackers can exploit this flaw to embed arbitrary web scripts into pages. These scripts are executed whenever a user accesses a compromised page, potentially leading to a range of security problems, including session hijacking and data theft.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SlimStat Analytics * <= 5.2.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved