Vulnerability Report: Arbitrary File Deletion in Perfmatters Plugin
On March 1, 2026, a serious vulnerability was identified in the Perfmatters plugin for WordPress, which has over 200,000 active installations. This flaw allows unauthenticated attackers to delete any file on the server, including critical files like wp-config.php. Such access could lead to complete website takeover.
The affected versions of the plugin are 2.5.9.1 and earlier. The vulnerability was reported by researcher hoshino through the Wordfence Bug Bounty Program, earning a reward of $3,726.
A patch was released on March 25, 2026, in version 2.6.0, which includes added security checks to prevent unauthorized file deletion. Users are urged to update their plugins immediately to mitigate this risk.
Risk Level: High – Immediate action is recommended to protect your website.
Source: View Original Report
