Performance Lab
Performance Lab has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Performance Lab has a vendor fix available, so running the current release closes it.
All of these findings were reported by Muhammad Daffa. Performance Lab is installed on roughly 100,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2022-47174Performance Lab <= 2.2.0 - Cross-Site Request Forgery via dismiss-wp-pointer
Read the full analysisVulnerability Records

Performance Lab
Author
WordPress Performance Team
The Performance Lab plugin is a collection of features focused on enhancing the performance of your site, most of which should eventually be merged into WordPress core. The plugin facilitates the discovery and activation of the individual performance feature plugins which the performance team is developing. In this way you can test the features to get their benefits before they become available in WordPress core. You can also play an important role by providing feedback to further improve the solutions. The feature plugins which are currently featured by this plugin are: Embed Optimizer Enhanced Responsive Images Image Placeholders Image Prioritizer Instant Back/Forward Modern Image Formats Optimization Detective (dependency for Embed Optimizer and Image Prioritizer) Performant Translations Speculative Loading View Transitions (experimental) These plugins can also be installed separately from installing Performance Lab, but having the Performance Lab plugin also active will ensure you find out about new performance features as they are developed.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C