{"id":"CVE-2026-4350","title":"The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1","summary":"The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","cwe":["CWE-22"],"published":"2026-04-03","updated":"2026-07-21","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-4350","references":[{"url":"https://perfmatters.io/docs/changelog/","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/58b9dab8-8539-4b53-b08d-f6ee3e1e744c?source=cve","label":"security@wordfence.com"}],"tags":["nvd","exploit-available"],"epss":0.00658,"epssPercentile":0.49713,"ingestedAt":"2026-07-21T19:53:39.470Z","exploits":{"github":1,"githubRepos":["https://github.com/whyiamsobusy/CVE-2026-4350"],"checkedAt":"2026-09-21T15:28:56.404Z"},"exploitAvailable":true,"slug":"CVE-2026-4350","body":"## Overview\n\nThe Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter without any sanitization, authorization check, or nonce verification. The unsanitized filename is concatenated with the storage directory path and passed to `unlink()`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server by using `../` path traversal sequences, including `wp-config.php` which would force WordPress into the installation wizard and allow full site takeover.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":5216,"id":"CVE-2026-4350","ts":1788887254017,"field":"exploit_available","old":"false","new":"true"},{"seq":4099,"id":"CVE-2026-4350","ts":1788886369869,"field":"exploit_available","old":"true","new":"false"},{"seq":2875,"id":"CVE-2026-4350","ts":1788883036205,"field":"exploit_available","old":"false","new":"true"},{"seq":1904,"id":"CVE-2026-4350","ts":1788882439286,"field":"exploit_available","old":"true","new":"false"},{"seq":997,"id":"CVE-2026-4350","ts":1788881873576,"field":"exploit_available","old":"false","new":"true"}]}