johnbillion/query-monitor
The developer tools panel for WordPress and WooCommerce
Activity
- Latest release
- 2mo ago
- Total releases
- 119
- Cadence
- ~11 days
- Last 12 months
- 17
Reach
- Stars
- 1.8k
Details
- License
- unknown
- First release
- Nov 19, 2013
| Version | Released | |
|---|---|---|
4.0.7
patch
| ||
4.0.6
patch
| ||
4.0.5
patch
| ||
4.0.4
patch
| ||
4.0.3
patch
| ||
4.0.2
patch
| ||
4.0.1
patch
| ||
4.0.0
major
| ||
4.0.0-beta.3
pre
| ||
4.0.0-beta.2
pre
| ||
3.20.4
patch
| ||
3.20.3
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
4.0.0-beta.1
pre
| ||
4.0.0-alpha.2
pre
| ||
4.0.0-alpha.1
pre
| ||
3.20.2
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.20.1
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.20.0
minor
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.19.0
minor
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.18.0
minor
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.17.2
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.17.1
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.17.0
minor
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.16.4
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.16.3
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.16.2
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.16.1
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.16.0
minor
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.15.0
minor
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.14.1
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.14.0
minor
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.13.1
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.13.0
minor
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.12.3
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.12.2
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.12.1
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.12.0
minor
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.11.2
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.11.1
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.11.0
minor
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.10.1
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.10.0
minor
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.9.0
minor
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.8.2
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.8.1
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.8.0
minor
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.7.1
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.7.0
minor
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.6.8
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev | ||
3.6.7
patch
1 CVE
CVE-2026-4267
GHSA-2xr4-chcf-vmvf
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactThe Query Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the On admin requests, the plugin reads user controlled data from PatchesThis issue has been patched in Query Monitor 3.20.4. CreditsMany thanks to Dmitrii Ignatyev at CleanTalk for responsibly disclosing this vulnerability. How can I report a security bug?You can submit a private security vulnerability report to Query Monitor via the Security tab on the GitHub repo. The GitHub Security Advisory process facilitates private collaboration on security issues. You'll receive credit for a valid report and a CVE if necessary. Affected versions
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.12.0
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
+ 93 more Show less
2.14.0
2.15.0
2.16.0
2.16.1
2.16.2
2.17.0
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6
2.6.1
2.6.10
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.0.1
3.1.0
3.1.1
3.10.0
3.10.1
3.11.0
3.11.1
3.11.2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.2.0
3.2.1
3.2.2
3.20.0
3.20.1
3.20.2
3.20.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.4.0
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.7.0
3.7.1
3.8.0
3.8.1
3.8.2
3.9.0
Fixed in
3.20.4
References Updated Mar 19, 2026 · Source: OSV.dev |