CVE-2026-4350

Perfmatters <= 2.5.9.1 - Authenticated (Subscriber+) Arbitrary File Deletion via 'delete' Parameter

The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter without any sanitization, authorization check, or nonce verification. The unsanitized filename is concatenated with the storage directory path and passed to `unlink()`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server by using `../` path traversal sequences, including `wp-config.php` which would force WordPress into the installation wizard and allow full site takeover.


We have discovered 17,092 live websites that are affected by CVE-2026-4350.

Run a Free Instant Scan




Affected Software

Product  Perfmatters
Category Wordpress Plugins
Vulnerable Domains17,092 live websites (100% of Perfmatters install base)
Vulnerable Versions
  • from 0 through 2.5.9.1
Vulnerable Versions Count153 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')



Details

  • Published - Apr 3, 2026
  • Updated - Apr 8, 2026

Credits

  • Phú (finder)

Website Distribution by Country

Number of websites using CVE-2026-4350
United States8,901 websites



Germany1,049 websites
GB872 websites
France497 websites
Netherlands454 websites
Spain451 websites
Canada428 websites
Australia427 websites
Iran366 websites
Brazil315 websites

Website Distribution by TLD

Number of websites using CVE-2026-4350
.com9,518 websites
.org722 websites
.de629 websites
.co.uk621 websites
.com.au444 websites
.nl422 websites
.net359 websites
.com.br295 websites
.fr266 websites
.pl237 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-4350

Top websites that are affected by CVE-2026-4350. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com United States*,***
**********.com United States*,***
**********.com United States*,***
***********.com United States*,***
*************.com United States*,***
********.com United States*,***
***************.net United States*,***
*******.com United States*,***
************.org France*,***
*******.com Canada*,***
See full domain list

FAQ

CVE-2026-4350 is Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Perfmatters
A total of 17,092 websites have been identified as vulnerable to CVE-2026-4350, based on global website indexing conducted by WebTechSurvey.
The Perfmatters is affected by the CVE-2026-4350 vulnerability.
Perfmatters versions up to and including 2.5.9.1 are vulnerable to CVE-2026-4350.