CVE-2026-4350 PUBLISHED

Perfmatters <= 2.5.9.1 - Authenticated (Subscriber+) Arbitrary File Deletion via 'delete' Parameter

Assigner: Wordfence
Reserved: 17.03.2026 Published: 03.04.2026 Updated: 03.04.2026

The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the PMCS::action_handler() method processing the $_GET['delete'] parameter without any sanitization, authorization check, or nonce verification. The unsanitized filename is concatenated with the storage directory path and passed to unlink(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server by using ../ path traversal sequences, including wp-config.php which would force WordPress into the installation wizard and allow full site takeover.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS Score: 8.1

Product Status

Vendor perfmatters
Product Perfmatters
Versions Default: unaffected
  • affected from 0 to 2.5.9.1 (incl.)

Credits

  • Phú finder

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE