Junglewise Threat Intelligence

CVE-2026-13251: Perfmatters WordPress plugin directory traversal in Local Google Fonts

CVE-2026-13251 · Severity: high · CVSS 7.5 · Published 2026-07-02

Technologies: Perfmatters. Vendors: Perfmatters.

Executive brief

Perfmatters, a performance optimization plugin for WordPress, contains a security flaw that allows unauthorized individuals to view sensitive files on the web server. By exploiting this vulnerability, an attacker could potentially access configuration files containing database credentials or other private system data. This issue specifically affects sites where the 'Local Google Fonts' and RSS feed features are enabled.

Technical details

A directory traversal vulnerability exists in the Perfmatters plugin for WordPress due to insufficient validation of the 's' parameter within the Local Google Fonts feature. An unauthenticated attacker can exploit this by sending a specially crafted request to read sensitive files (such as wp-config.php) from the server's filesystem. Successful exploitation requires specific preconditions: the Local Google Fonts feature must be enabled (it is disabled by default), 'pretty permalinks' must be active, and RSS feed links must remain enabled in the plugin settings. The vulnerability was addressed in version 2.6.5 by adding domain verification and content type validation to the font downloading logic.

Affected products

  • perfmatters Perfmatters up to, and including, 2.6.4

Timeline

  • 2026-06-30: patched: Fixed in version 2.6.5
  • 2026-07-02: disclosed: NVD publication date

References

Related threats