All verified exploits

CVE-2026-1238 Unauthenticated Stored XSS via Fingerprint Tracking

Deterministic high WordPress Added cve-verified-cve-2026-1238

Detects WordPress installs running the SlimStat Analytics plugin (wp-slimstat) at version 5.3.5 or earlier. The plugin's AJAX tracking endpoint accepts a browser fingerprint (fh parameter) from unauthenticated visitors. The value passes through sanitize_text_field() which does not strip attribute-injection characters, then is rendered unescaped in the admin Access Log dashboard's title attribute. An attacker can inject JavaScript that executes when any admin views the analytics page, enabling session hijacking and full admin takeover.

Related WordPress exploits

Is your app exploitable through CVE-2026-1238?

Scan your domain free