A vulnerability, which was classified as problematic , has been found in Query Monitor Plugin on WordPress. This vulnerability affects unknown code. This manipulation of the argument REQUEST_URI causes cross site scripting. This vulnerability appears as CVE-2026-4267 . The attack may be initiated remotely. There is no available exploit. It is advisable to upgrade the affected component.