Impact
The perfmatters WordPress plugin versions 2.6.4 and earlier contain an unauthenticated cross‑site scripting flaw. The vulnerability permits an attacker to deliver arbitrary JavaScript to a visitor’s browser by exploiting unsanitized user input. No authentication is required to trigger the flaw, making it accessible to any user. The impact is that malicious code can execute client‑side within the victim’s browser; the description confirms the existence of the XSS but does not detail further exploitation outcomes.
Affected Systems
WordPress installations that have the perfmatters plugin installed at version 2.6.4 or earlier are affected. The vulnerability does not require administrative privileges; any unauthenticated user can trigger the exploit by interacting with the plugin.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, yet the EPSS score of less than 1 % points to a very low probability of widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed active exploitation. Based on the description it is inferred that the flaw likely involves user‑supplied input that the plugin reflects or executes without proper sanitization, enabling attackers to deliver malicious JavaScript to unsuspecting visitors.
OpenCVE Enrichment