Executive brief
VeronaLabs Slimstat Analytics, a popular WordPress plugin used for website traffic analysis, is vulnerable to a security flaw that could allow an attacker to access sensitive database information. By exploiting this vulnerability, a logged-in user with minimal permissions (such as a subscriber) could potentially steal customer data, site configurations, or other private information stored in the website's database. This could lead to significant data breaches and loss of confidentiality for affected organizations.
Technical details
A Blind SQL Injection vulnerability exists in the VeronaLabs Slimstat Analytics plugin for WordPress (versions up to and including 5.4.11) due to improper neutralization of special elements in SQL commands. The flaw allows an authenticated attacker with 'Subscriber' level privileges or higher to execute arbitrary SQL queries against the backend database via network requests. Because it is a 'blind' injection, the attacker can infer data by observing differences in application responses or timing. This can lead to the unauthorized extraction of sensitive information, including user credentials and site metadata. The issue is resolved in version 5.4.12.
Affected products
- VeronaLabs Slimstat Analytics through 5.4.11
Timeline
- 2026-04-18: other: Vulnerability reported by researcher hhhai
- 2026-06-17: advisory: Advisory published by Patchstack and NVD
- 2026-06-17: patched: Patch released in version 5.4.12