200,000+ Sites at Risk: Perfmatters Flaw Enables Full WordPress Site Takeover
ID: ba1b1615-0949-5a2a-8150-e0afe78bed61
STIX ID: report--ba1b1615-0949-5a2a-8150-e0afe78bed61
Feed Name: securityonline.info
Threat Score
Researchers disclosed CVE-2026-4350 in the Perfmatters WordPress plugin (200,000+ installs): an unauthenticated path-traversal via the plugin's snippet delete handler allows arbitrary file read/delete (including wp-config.php), enabling site reset and takeover; the vendor patched the flaw in Perfmatters v2.6.0 by adding sanitization, admin capability checks, and nonce verification.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
