CVE-2026-13251
Last modified
CVE-2026-13251 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.4 via the 's' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. EPSS estimates a 0.82% chance of exploitation in the next 30 days.
Description
The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.4 via the 's' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires the Local Google Fonts feature to be enabled (disabled by default), pretty permalinks to be active, and RSS feed links to remain enabled in the plugin settings.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| perfmatters | Perfmatters | <= 2.6.4 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-13251?
How severe is CVE-2026-13251?
How do I fix CVE-2026-13251?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-13246The GiveWP – Donation Plugin and Fundraising Platform plugin…6.4
- CVE-2026-13247The Logo Slider – Logo Carousel, Client Logo Slider & Brand …6.4
- CVE-2026-13248An Authenticated Remote Code Execution via Arbitrary File Wr…8.8
- CVE-2026-13249An unauthenticated Remote Code Execution via Arbitrary File …9.8
- CVE-2026-1325A security flaw has been discovered in Sangfor Operation and…9.8
- CVE-2026-13250The Solace Extra plugin for WordPress is vulnerable to autho…5.3
- CVE-2026-13252The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, N…6.4
- CVE-2026-13253The Ultimate Post plugin for WordPress is vulnerable to Stor…6.4
- CVE-2026-1326A weakness has been identified in Totolink NR1800X 9.1.0u.62…8.8
- CVE-2026-13260IBM Verify Identity Access could allow a remote attacker to …7.5
- CVE-2026-13262The Majestic Support – The Leading-Edge Help Desk & Customer…6.5
- CVE-2026-13265IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.4…6.8
Are you affected by CVE-2026-13251?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
