Vulnerability Details: Persistent Cross-Site Scripting (XSS) in Slimstat Analytics
Yesterday a new release of the plugin Slimstat Analytics included a changelog entry “[Fix] Addressed a remote XSS vulnerability disclosed by Sucuri/GoDaddy.”, but Sucuri doesn’t seem to have disclosed any vulnerability, so it isn’t clear what that referred to. In the subversion entry logged “Addressed a remote XSS vulnerability disclosed by Sucuri/GoDaddy” no code was changed. When we did a quick check over the code that was actually changed yesterday we were confused as to how what looks like it was related to that could be a vulnerability, but upon more thorough check we realized code that it was different code that related to that and the change made doesn’t seem ideal to address the persistent cross-site scripting (XSS) vulnerability in question.
...
This post provides insights on a vulnerability in the WordPress plugin Slimstat Analytics not discovered by us, where the discoverer hadn't provided the details needed for us to confirm the vulnerability while we were adding it to the data set for our service, so the rest of its contents are limited to subscribers of our service.
If you were using our service, you would have already been warned about this vulnerability if your website is vulnerable due to it. You can try out our service for free and then see the rest of the details of the vulnerability.
For existing customers, please log in to your account to view the rest of the contents of the post.