PT-2025-52436 · WordPress · Slimstat Analytics

Supakiad S

·

Published

2025-12-19

·

Updated

2025-12-19

·

CVE-2025-14151

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SlimStat Analytics plugin for WordPress versions prior to 5.3.3
Description The SlimStat Analytics plugin for WordPress is susceptible to Stored Cross-Site Scripting. This is caused by inadequate input sanitization and output escaping of user-provided attributes. An unauthenticated attacker can inject arbitrary web scripts via the outbound resource parameter in the 'slimtrack' AJAX action. When a user accesses an injected page, the malicious script will execute.
Recommendations Update the SlimStat Analytics plugin to version 5.3.3 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-14151

Affected Products

Slimstat Analytics