Junglewise Threat Intelligence

CVE-2026-4350: Perfmatters arbitrary file deletion via path traversal in PMCS::action_handler

CVE-2026-4350 · Severity: high · CVSS 8.1 · Published 2026-04-03

Technologies: Perfmatters. Vendors: Perfmatters.

Executive brief

Perfmatters, a WordPress plugin used for site speed optimization, contains a security flaw that allows users with basic account access (such as subscribers) to delete files from the web server. By deleting critical system files like the WordPress configuration file, an attacker can force the website into a setup state and take full control of the site. This could lead to a complete site takeover, data loss, and service disruption.

Technical details

A path traversal vulnerability exists in the `PMCS::action_handler()` method of the Perfmatters plugin due to insufficient sanitization of the `delete` GET parameter. The application fails to perform authorization checks or nonce verification before concatenating the user-supplied filename with the storage directory path and passing it to the PHP `unlink()` function. Authenticated attackers with Subscriber-level permissions or higher can use `../` sequences to delete arbitrary files on the server. A common exploit path involves deleting `wp-config.php`, which triggers the WordPress installation wizard and allows the attacker to reconfigure the site and gain administrative control. The issue is addressed in versions following 2.5.9.1.

Affected products

  • perfmatters Perfmatters up to, and including, 2.5.9.1

Timeline

  • 2026-03-25: patched: Version 2.6.0 released with minimum PHP requirement increase and library updates; subsequent security hardening followed in 2.6.4 and 2.6.5.
  • 2026-04-03: advisory: Initial disclosure by Wordfence and NVD.

References

Related threats