Junglewise Threat Intelligence

CVE-2026-56047: Perfmatters unauthenticated XSS in WordPress plugin

CVE-2026-56047 · Severity: high · CVSS 7.1 · Published 2026-06-26

Technologies: Perfmatters. Vendors: Perfmatters.

Executive brief

Perfmatters is a WordPress plugin designed to improve website performance by disabling unnecessary features and optimizing scripts. A security flaw in versions 2.6.3 and earlier allows an unauthenticated attacker to trick a user into executing malicious code in their browser. This could lead to unauthorized actions being performed on behalf of the user, such as redirecting visitors to malicious sites or stealing session information.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Perfmatters WordPress plugin due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject malicious scripts into the application. Successful exploitation requires a victim to interact with a specially crafted link or page. Once executed, the script runs within the context of the victim's browser session, potentially allowing the attacker to bypass same-origin policy protections and access sensitive data or perform administrative actions. The issue is resolved in version 2.6.4.

Affected products

  • Perfmatters perfmatters <= 2.6.3

Timeline

  • 2026-05-29: other: Reported by researcher dutafi
  • 2026-06-25: advisory: Patchstack advisory published
  • 2026-06-26: disclosed: NVD publication date

References

Related threats