CVE-2026-4350 is an arbitrary file deletion vulnerability in the Perfmatters plugin for WordPress affecting all versions up to and including 2.5.9.1. The flaw is in the PMCS::action_handler() method, which processes the $_GET['delete'] parameter without sanitization, authorization checks, or nonce verification. The supplied value is concatenated with the plugin storage directory path and passed directly to PHP's unlink() function. Because path traversal sequences such as ../ are not filtered, an authenticated attacker can cause deletion of files outside the intended directory. The issue is exploitable by users with Subscriber-level access and above. The lack of nonce verification also makes the vulnerable action susceptible to CSRF. Deletion of critical files such as wp-config.php can force WordPress into its installation flow, creating a practical path to full site takeover.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
wp-config.php forces WordPress into the installation wizard, which can then be abused to reconfigure the site and obtain full administrative control, resulting in complete site takeover.If you can’t patch tonight, do this now.
wp-config.php where operationally feasible. Use CSRF protections at the application or edge layer where possible, and monitor for suspicious requests containing traversal sequences in the delete parameter. These are temporary measures; upgrading to 2.6.0 or later is the proper fix.Patch, then assume compromise.
normalize_snippet_file_name() helper, array normalization for bulk operations, and validation in Snippet::delete().1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit package for CVE-2026-4350, an arbitrary file deletion vulnerability in the Perfmatters WordPress plugin affecting versions <= 2.5.9.1. The main exploit is exploit/exploit.py, a Python script using the requests library to send GET requests to the WordPress AJAX endpoint /wp-admin/admin-ajax.php with action=perfmatters_delete and a traversal-based delete parameter. It iterates over two hardcoded targets, ../../../../wp-config.php and ../../../../.htaccess, and prints HTTP status codes for each request. This gives the exploit operational capability to attempt deletion of critical WordPress files, which can break the site, cause denial of service, and potentially enable takeover scenarios. Repository structure is straightforward: README.md describes the CVE and usage; exploit/exploit.py is the primary exploit; poc/poc.sh is a minimal curl-based proof of concept targeting wp-config.php; nuclei/cve-2026-4350.yaml is a nuclei template that reproduces the same request pattern for scanning/detection; docs/analysis.md, docs/impact.md, and docs/mitigation.md provide brief supporting documentation; vulnerable-setup/docker-compose.yml defines a simple WordPress container exposed on port 8080 for testing. The repository is not tied to a major exploit framework, though it includes a nuclei template as an auxiliary artifact. The exploit is a real web attack against a WordPress plugin endpoint, not merely a detector. However, its payloads are basic and hardcoded rather than customizable, so OPERATIONAL is the best maturity fit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.