logo

200,000+ Sites at Risk: Perfmatters Flaw Enables Full WordPress Site Takeover

ID: ba1b1615-0949-5a2a-8150-e0afe78bed61

STIX ID: report--ba1b1615-0949-5a2a-8150-e0afe78bed61

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-03

Date Updated: 2026-04-23

Author: Ddos

...
...

Researchers disclosed CVE-2026-4350 in the Perfmatters WordPress plugin (200,000+ installs): an unauthenticated path-traversal via the plugin's snippet delete handler allows arbitrary file read/delete (including wp-config.php), enabling site reset and takeover; the vendor patched the flaw in Perfmatters v2.6.0 by adding sanitization, admin capability checks, and nonce verification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.