Impact
The perfmatters WordPress plugin versions 2.6.4 and earlier contain an unauthenticated cross‑site scripting flaw as noted in the CVE description. Because this issue allows malicious code to be executed within the client's browser, it can lead to cookie theft, session hijacking, defacement, or phishing against site visitors.
Affected Systems
WordPress installations that have the perfmatters plugin installed at version 2.6.4 or earlier are affected. The vulnerability does not require administrative privileges; any unauthenticated user can trigger the exploit by interacting with the plugin.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, yet the EPSS score of less than 1 % points to a very low probability of widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed active exploitation. Based on the description it is inferred that the flaw likely involves user-supplied input that the plugin reflects or executes without proper sanitization, enabling attackers to deliver malicious JavaScript to unsuspecting visitors.
OpenCVE Enrichment