PT-2026-54943 · WordPress · Perfmatters
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Perfmatters versions prior to 2.6.5
Description
The Perfmatters plugin for WordPress contains a Directory Traversal flaw, which occurs when an application fails to properly sanitize user-supplied input used to construct file paths. This allows unauthenticated attackers to read arbitrary files on the server that may contain sensitive information via the
s parameter. Successful exploitation requires the Local Google Fonts feature to be enabled, pretty permalinks to be active, and RSS feed links to be enabled in the plugin settings.Recommendations
Update the plugin to version 2.6.5 or later.
As a temporary mitigation, disable the Local Google Fonts feature, deactivate pretty permalinks, or disable RSS feed links in the plugin settings.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Perfmatters