200K Sites at Risk: Perfmatters Plugin Arbitrary File Deletion

Date:

Vulnerability Report: Arbitrary File Deletion in Perfmatters Plugin

On March 1, 2026, a serious vulnerability was identified in the Perfmatters plugin for WordPress, which has over 200,000 active installations. This flaw allows unauthenticated attackers to delete any file on the server, including critical files like wp-config.php. Such access could lead to complete website takeover.

The affected versions of the plugin are 2.5.9.1 and earlier. The vulnerability was reported by researcher hoshino through the Wordfence Bug Bounty Program, earning a reward of $3,726.

A patch was released on March 25, 2026, in version 2.6.0, which includes added security checks to prevent unauthorized file deletion. Users are urged to update their plugins immediately to mitigate this risk.

Risk Level: High – Immediate action is recommended to protect your website.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...