CVE-2026-4350Patch

LOWCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter without any sanitization, authorization check, or nonce verification. The unsanitized filename is concatenated with the storage directory path and passed to `unlink()`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server by using `../` path traversal sequences, including `wp-config.php` which would force WordPress into the installation wizard and allow full site takeover.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: declining

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 6 mentions (2026-04-03); latest day: 1
  • 9 total mentions across 4 days

Deep dive

Activity timeline9 mentions / 4d
02356Mentions · 2026-04-03: 6Mentions · 2026-04-04: 1Mentions · 2026-04-07: 1Mentions · 2026-04-10: 1PoC Mentioned / Linked · 2026-04-07: 1Patch / Workaround · 2026-04-03: 3Patch / Workaround · 2026-04-04: 1Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-03: 6Technical Details · 2026-04-07: 104-0304-0404-0704-10
Signal classification3 categories
Patch
555.6%
Disclosure
333.3%
PoC
111.1%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-036
Disclosure3Patch3
2026-04-041
Patch1
2026-04-071
PoC1
2026-04-101
Patch1
Full discourse9 posts
  • DFIR Radar@DFIR_Radar
    Patch

    Critical arbitrary file deletion flaw in Perfmatters WordPress plugin (CVE-2026-4350, CVSS 8.1) affects 200,000+ sites. Unauthenticated attackers can delete wp-config.php for full site takeover. Update to version 2.6.0 immediately. #DFIR_Radar https://t.co/u9743eyFvy

    Post summary

    A critical file-deletion flaw (CVE-2026-4350) in the Perfmatters WordPress plugin allows unauthenticated attackers to delete wp-config.php, enabling full site takeover; users are urged to update to v2.6.0 immediately.

    10010147
    1.2K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    20万サイト以上が使用するWordPressのPerfmattersプラグインに深刻な脆弱性。CVE-2026-4350はCVSSスコア8.1(???)で、遠隔からサーバ上の任意のファイルを無認証で読み込み及び削除可能なもの。スニペット削除時のチェックが多数欠落しているのが悪い。2.6.0で修正。 https://securityonline.info/perfmatters-vulnerability-200k-sites-full-takeover-cve-2026-4350/

    Post summary

    CVE‑2026‑4350 exposes unauthenticated remote file read and delete in WordPress Perfmatters; the flaw was addressed in plugin version 2.6.0.

    00011814
    7.3K followersView on X
  • Argus Panoptes@Argus_pd
    Patch

    Signal cleanup: CVE-2026-4350 (Perfmatters) is real, but not every '200k sites at risk' post proves active mass exploitation. Patch fast, then verify exposure by version/auth path before reposting. Sources: NVD https://nvd.nist.gov/vuln/detail/CVE-2026-4350 + CISA KEV catalog

    Post summary

    The message confirms CVE‑2026‑4350 is legitimate, stresses the need to apply a patch rapidly, and clarifies there is no evidence of widespread active exploitation.

    0000048
    6 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-4350-perfmatters-version-2-5-9-1-high-vulnerability-proof-of-concept CVE-2026-4350 #WordPress plugin #vulnerability perfmatters #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The text announces a proof of concept for CVE-2026-4350 impacting the Perfmatters plugin, indicating a high severity vulnerability but providing no details on exploit code, active exploitation, or patch availability.

    0000037
    6 followersView on X
  • StrongKeep Cybersecurity@StrongKeepCyber
    Patch

    WordPress plugin flaw puts 200k+ sites at risk. Perfmatters CVE-2026-4350 could allow full site takeover. If you run a small business site, check plugin updates, disable unused plugins, and review access rights. Read more: https://securityonline.info/perfmatters-vulnerability-200k-sites-full-takeover-cve-2026-4350/

    Post summary

    The article alerts that Perfmatters CVE‑2026‑4350 may enable full WordPress site takeover, and recommends updating or disabling the plugin and tightening access rights.

    0000041
    3 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4350 The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS… https://www.cve.org/CVERecord?id=CVE-2026-4350

    Post summary

    The Perfmatters WordPress plugin is vulnerable to path traversal that allows arbitrary file deletion in all versions up to 2.5.9.1.

    0000042
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4350 - Perfmatters <= 2.5.9.1 - Authenticated (Subscriber+) Arbitrary File Deletion via 'delete' Parameter Intel Report: https://ift.tt/snLqJXh

    Post summary

    Threat alert identifies CVE-2026-4350, allowing authenticated subscribers to delete arbitrary files through the 'delete' parameter in Perfmatters <= 2.5.9.1; no active exploitation or patch details are noted.

    0000063
    281 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4350 - High The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` meth... https://www.thehackerwire.com/vulnerability/CVE-2026-4350/ https://t.co/8iAGh8EMOS

    Post summary

    The post announces that Perfmatters plugin for WordPress is vulnerable to path traversal leading to arbitrary file deletion in all versions up to 2.5.9.1, with no mention of exploitation, patch, or PoC.

    0000050
    163 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    A critical 8.1 CVSS flaw in Perfmatters (200k+ installs) allows unauthenticated attackers to delete wp-config.php and hijack sites. Update to 2.6.0 now! #Perfmatters #WordPressSecurity #InfoSec #CyberSecurity #Vulnerability #CVE #WebSecurity #WordPress https://securityonline.info/perfmatters-vulnerability-200k-sites-full-takeover-cve-2026-4350/ https://t.co/uLgU99xMWM

    Post summary

    A high‑severity vulnerability (CVSS 8.1) in the Perfmatters WordPress plugin permits unauthenticated attackers to delete wp-config.php and take over sites; a patch (version 2.6.0) is recommended.

    00000284
    11.0K followersView on X

Explore more