CVE · High

CVE-2026-56047 — Perfmatters [perfmatters] < 2.6.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-56047 Perfmatters [perfmatters] < 2.6.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 2.6.4 2.6.4 2026-06-25

CVE-2026-56047

The Perfmatters plugin for WordPress contains a security flaw affecting versions up to 2.6.3, which allows malicious scripts to be injected into pages through a specific type of attack. This vulnerability occurs when the plugin fails to properly filter and protect user input from being executed as code on the site. As a result, attackers can potentially exploit this weakness by manipulating users into performing certain actions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.