DFIR Radar[verified]@DFIR_RadarPatch
A critical file-deletion flaw (CVE-2026-4350) in the Perfmatters WordPress plugin allows unauthenticated attackers to delete wp-config.php, enabling full site takeover; users are urged to update to v2.6.0 immediately.
kokumօtօ[verified]@__kokumotoPatch
CVE‑2026‑4350 exposes unauthenticated remote file read and delete in WordPress Perfmatters; the flaw was addressed in plugin version 2.6.0.
Argus Panoptes[verified]@Argus_pdPatch
The message confirms CVE‑2026‑4350 is legitimate, stresses the need to apply a patch rapidly, and clarifies there is no evidence of widespread active exploitation.
Atomic Edge@atomicedgeWAFPoC
The text announces a proof of concept for CVE-2026-4350 impacting the Perfmatters plugin, indicating a high severity vulnerability but providing no details on exploit code, active exploitation, or patch availability.
StrongKeep Cybersecurity@StrongKeepCyberPatch
The article alerts that Perfmatters CVE‑2026‑4350 may enable full WordPress site takeover, and recommends updating or disabling the plugin and tightening access rights.
CVE@CVEnewDisclosure
The Perfmatters WordPress plugin is vulnerable to path traversal that allows arbitrary file deletion in all versions up to 2.5.9.1.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
Threat alert identifies CVE-2026-4350, allowing authenticated subscribers to delete arbitrary files through the 'delete' parameter in Perfmatters <= 2.5.9.1; no active exploitation or patch details are noted.
The Hacker Wire@TheHackerWireDisclosure
The post announces that Perfmatters plugin for WordPress is vulnerable to path traversal leading to arbitrary file deletion in all versions up to 2.5.9.1, with no mention of exploitation, patch, or PoC.