The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter without any sanitization, authorization check, or nonce verification. The unsanitized filename is concatenated with the storage directory path and passed to `unlink()`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server by using `../` path traversal sequences, including `wp-config.php` which would force WordPress into the installation wizard and allow full site takeover.
[POC] MAL-2026-2307 — CVE-2026-43503
DirtyClone - local privilege escalation (LPE) proof-of-concept targeting a kernel/XFRM-related vulnerability described in the source as CVE-2026-43503
[POC] GHSA-3mgp-fx93-9xv5 — CVE-2026-43503
CVE-2026-43503
[POC] CVE-2026-43500 — CVE-2026-43500
CVE-2026-43500 / CVE-2026-31431 / CVE-2026-43284 golang hotfix
[POC] CVE-2026-43284 — CVE-2026-43284-CVE-2026-43500-scan
Dirtyfrag CVE-2026-43284 & CVE-2026-43500 Scan
[POC] CVE-2026-43500 — dirty_frag_mitigation
A bash script for mitigating linux dirty frag exploit CVE-2026-43500
[POC] CVE-2026-4350 — CVE-2026-4350
CVE-2026-4350 - Perfmatters WordPress Arbitrary File Deletion
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free