PT-2026-54943 · WordPress · Perfmatters

·

CVE-2026-13251

·

Published

2026-07-02

·

Updated

2026-07-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Perfmatters versions prior to 2.6.5
Description The Perfmatters plugin for WordPress contains a Directory Traversal flaw, which occurs when an application fails to properly sanitize user-supplied input used to construct file paths. This allows unauthenticated attackers to read arbitrary files on the server that may contain sensitive information via the s parameter. Successful exploitation requires the Local Google Fonts feature to be enabled, pretty permalinks to be active, and RSS feed links to be enabled in the plugin settings.
Recommendations Update the plugin to version 2.6.5 or later. As a temporary mitigation, disable the Local Google Fonts feature, deactivate pretty permalinks, or disable RSS feed links in the plugin settings.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13251

Affected Products

Perfmatters