Detects WordPress installs running the SlimStat Analytics plugin (wp-slimstat) at version 5.3.5 or earlier. The plugin's AJAX tracking endpoint accepts a browser fingerprint (fh parameter) from unauthenticated visitors. The value passes through sanitize_text_field() which does not strip attribute-injection characters, then is rendered unescaped in the admin Access Log dashboard's title attribute. An attacker can inject JavaScript that executes when any admin views the analytics page, enabling session hijacking and full admin takeover.
Is your app exploitable through CVE-2026-1238?
Scan your domain free