Vibes

Vibes has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 7.5, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is SQL Injection, behind 1 of the records (100%).

The one issue recorded for Vibes has a vendor fix available, so running the current release closes it.

All of these findings were reported by Jonas Benjamin Friedli. Vibes is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSHigh
7.5/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Vibes vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.5CVE-2025-9172

Vibes <= 2.2.0 - Unauthenticated SQL Injection via `resource` Parameter

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv2.5.0
5.0(2)
100/100
Last Updated
2026-08-18 (25d ago)
Active Installs
300+
Downloads
19,513
Requires WP
6.4+
Requires PHP
8.2+
Tested up to
WP 7.1
Created
2021-12-06 (5y ago)

Truthful user experience and browsing performances monitoring. Vibes is a robust user experience and browsing performances monitoring solution that analyzes perceived performances from users’ viewpoint. It is fully autonomous – does not rely on external services and does not require any API keys, works on any type of hosting and in any type of environment – including staging, intranets or password protected sites. By continuously monitoring user experience, Vibes can report: navigation performance KPIs per pages – like latency, redirections, browser caching hit rates, etc.; network timelines as if you were in the dev tools of your users’ browsers; resources details – like initiators, protocols, mime types, average sizes, etc.; Web Vitals: LCP, FID, CLS, FCP and TTFB. It can segment all this data per: user type (anonymous vs. authenticated); channel (frontend vs. backend); country (requires the free IP Locator plugin); device classes and types (requires the free Device Detector plugin). Vibes supports multisite report delegation (see FAQ). Vibes supports WP-CLI commands to: display (past or current) performances signals in console – see wp help vibes tail for details; toggle on/off main settings – see wp help vibes settings for details. For a full help on WP-CLI commands in Vibes, please read this guide. Vibes is part of PerfOps One, a suite of free and open source WordPress plugins dedicated to observability and operations performance. Vibes is a free and open source plugin for WordPress. It integrates many other free and open source works (as-is or modified). Please, see &#8216;about’ tab in the plugin settings to see the details. Support This plugin is free and provided without warranty of any kind. Use it at your own risk, I’m not responsible for any improper use of this plugin, nor for any damage it might cause to your site. Always backup all your data before installing a new plugin. Anyway, I’ll be glad to help you if you encounter issues when using this plugin. Please read carefully the FAQ at the bottom of this page before requesting support. Donation If you like this plugin or find it useful and want to thank me for the work done, please consider making a donation to La Quadrature Du Net or the Electronic Frontier Foundation which are advocacy groups defending the rights and freedoms of citizens on the Internet. By supporting them, you help the daily actions they perform to defend our fundamental freedoms!

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C