CVE-2026-1238Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) parameter in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-19); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-19: 3Mentions · 2026-06-12: 1Mentions · 2026-06-13: 1Patch / Workaround · 2026-06-12: 1Technical Details · 2026-03-19: 2Technical Details · 2026-06-12: 1Technical Details · 2026-06-13: 103-1906-1206-13
Signal classification1 categories
Disclosure
5100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-193
Disclosure3
2026-06-121
Disclosure1
2026-06-131
Disclosure1
Full discourse5 posts
  • takenaka hiroya@Joe_Biden_ja
    Disclosure

    CVE-2026-1238、Adobe Acrobat ReaderにXSSの脆弱性。CVSSスコアは6.5。早急にアップデートを実施すべき。影響は大きい。

    Post summary

    The post discloses CVE-2026-1238, an XSS flaw in Adobe Acrobat Reader with a CVSS 6.5 score, and urges users to update immediately due to high impact.

    01010105
    564 followersView on X
  • takenaka hiroya@Joe_Biden_ja
    Disclosure

    CVE-2026-1238: Adobe製品に関連するゼロデイ脆弱性が確認され、影響は複数の主要製品。早急なパッチ情報のリリースが期待される。

    Post summary

    A zero‑day vulnerability (CVE‑2026‑1238) affecting several major Adobe products has been confirmed, with expectations of an imminent patch release.

    0000039
    564 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1238 Unauthenticated Stored XSS in SlimStat Analytics WordPress Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1238

    Post summary

    The text discloses a new stored XSS vulnerability in the SlimStat Analytics WordPress Plugin, specifying the vulnerability type and target, but does not mention any PoC, exploit, active exploitation, patch, or debunking.

    0000084
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1238 The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) parameter in all versions up to, and including, 5.3.… https://www.cve.org/CVERecord?id=CVE-2026-1238

    Post summary

    CVE-2026-1238 reveals a stored XSS in the SlimStat Analytics WordPress plugin (up to version 5.3) through the 'fh' parameter, with no evidence of exploitation or patching mentioned.

    00000123
    56.7K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-1238 - veronalabs - SlimStat Analytics - https://www.redpacketsecurity.com/cve-alert-cve-2026-1238-veronalabs-slimstat-analytics/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-1238 #veronalabs #slimstat-analytics

    Post summary

    The tweet announces a CVE alert for CVE‑2026‑1238 affecting veronalabs SlimStat Analytics, but provides no further technical specifics or evidence of exploitation.

    00000127
    3.6K followersView on X

Explore more