CVE-2026-4350

The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter without any sanitization, authorization check, or nonce verification. The unsanitized filename is concatenated with the storage directory path and passed to `unlink()`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server by using `../` path traversal sequences, including `wp-config.php` which would force WordPress into the installation wizard and allow full site takeover.
Configurations

No configuration.

History

03 Apr 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 08:16

Updated : 2026-04-24 18:13


NVD link : CVE-2026-4350

Mitre link : CVE-2026-4350

CVE.ORG link : CVE-2026-4350


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')