CVE-2023-0630: Wp-Slimstat Slimstat Analytics

High severity, CVSS 8.8. EPSS: 5.1% chance of exploitation in the next 30 days.

The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that concatenates attributes directly into an SQL query.

Affected products

  • Wp-Slimstat Slimstat Analytics: before 4.9.3.3 (fixed in 4.9.3.3)

Published 2023-03-20. Last modified 2026-06-17.