CVE-2026-4350 details a high-severity arbitrary file deletion vulnerability in the Perfmatters plugin for WordPress, affecting all versions up to 2.5.9.1. This flaw (CVSS 8.1) allows authenticated attackers with Subscriber-level access to exploit a path traversal vulnerability by manipulating an unsanitized GET parameter. Successful exploitation can lead to the deletion of critical server files, such as wp-config.php, potentially enabling a full site takeover. While there is no evidence of active exploitation or publicly available exploit code, the vulnerability has received some attention within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 2.5.9.1CPE match | cpe:2.3:a:perfmatters:perfmatters:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.