LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-4351 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: April 10, 2026

Perfmatters WordPress Plugin - Broken Access Control

Published: April 10, 2026Updated: April 10, 2026Remote Exploitable

Overview

Perfmatters WordPress plugin <= 2.5.9 contains an arbitrary file overwrite vulnerability caused by lack of authorization and nonce verification in PMCS::action_handler(), letting authenticated attackers with Subscriber-level access overwrite files, exploit requires Subscriber-level access or higher.

Severity & Score

Severity: High
CVSS Score: 8.1
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Authenticated attackers can overwrite arbitrary files, potentially causing denial of service by corrupting critical server files.

Mitigation

Update to the latest version beyond 2.5.9.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 10, 2026

🟠 CVE-2026-4351 - High (8.1) The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in all versions up to, and including, 2.5.9. This is due to the `PMCS::action_handler()` method processing the bulk action `activate`/`deactivate` ha... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-4351/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Apr 10, 2026

🟠 CVE-2026-4351 - High (8.1) The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in all versions up to, and including, 2.5.9. This is due to the `PMCS::action_handler()` method processing the bulk action `activate`/`deactivate` ha... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-4351/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-4351
Severity
High
CVSS Score
8.1
Type
broken_access_control
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-22

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days