CVE-2026-13251: Perfmatters WordPress Plugin Directory Traversal Vulnerability
A directory traversal vulnerability in the Perfmatters WordPress plugin allows attackers to read files they shouldn't have access to. An attacker can request arbitrary files on a server by manipulating a parameter in a specially crafted request, potentially exposing passwords, configuration files, or other sensitive data. The vulnerability affects all versions up to 2.6.4 and requires three specific conditions: the Local Google Fonts feature must be enabled, WordPress pretty permalinks must be active, and RSS feed links must remain enabled in plugin settings. No authentication is needed to exploit this flaw.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Weaknesses (CWE)
- CWE-22
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-07-02 / 2026-07-02
NVD description (verbatim)
The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.4 via the 's' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires the Local Google Fonts feature to be enabled (disabled by default), pretty permalinks to be active, and RSS feed links to remain enabled in the plugin settings.
3 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-13251 is a path traversal vulnerability (CWE-22) in Perfmatters versions ≤2.6.4 affecting the 's' parameter. The vulnerability allows unauthenticated attackers to bypass intended access controls and read arbitrary files on the server through directory traversal sequences. The attack vector is network-based with low attack complexity, requiring no user interaction. While the vulnerability exists in the plugin code, exploitation is gated by three environmental factors: the Local Google Fonts feature (disabled by default) must be enabled, WordPress must be configured with pretty permalinks, and RSS feed links must be active in plugin settings. This creates a conditional exposure profile where many default WordPress installations would not be exploitable.
Business impact
If exploited successfully, attackers can gain read access to sensitive server files, including database credentials stored in wp-config.php, authentication tokens, API keys, or other configuration data that could enable further compromise. In multi-tenant hosting environments, exploitation could potentially expose data from other sites. The impact is particularly severe if Local Google Fonts is intentionally enabled for performance reasons, as this feature may be active on high-traffic sites. Organizations running Perfmatters should prioritize assessment of their plugin configuration and whether the three prerequisite conditions are present.
Affected systems
WordPress installations using the Perfmatters plugin in versions 2.6.4 and earlier are technically vulnerable. However, actual exploitability depends on configuration: sites must have (1) Local Google Fonts feature enabled, (2) pretty permalinks enabled, and (3) RSS feed links enabled in plugin settings. The vulnerability was published July 2, 2026. WordPress ecosystem exposure is broad, but the conditional nature of exploitation reduces the immediate at-risk population to those with all three settings active.
Exploitability
The vulnerability has a CVSS 3.1 score of 7.5 (HIGH) due to its network accessibility and low attack complexity, but real-world exploitability requires meeting three conditions simultaneously. The Local Google Fonts feature is disabled by default, which provides initial friction. However, organizations that intentionally enable this feature for site performance—common in high-traffic WordPress sites—become fully exposed. No known public exploit code or KEV (Known Exploited Vulnerability) status exists as of the publication date, but the straightforward nature of directory traversal attacks suggests exploitation tooling could emerge quickly once researchers or attackers develop proof-of-concept demonstrations.
Remediation
Update the Perfmatters plugin to a version newer than 2.6.4 that includes a patch for this vulnerability. Until a patch is available, organizations can reduce risk by disabling the Local Google Fonts feature in the plugin settings, which eliminates the primary attack surface. Additionally, if operationally feasible, disabling pretty permalinks or RSS feed links will prevent exploitation, though these options may impact site functionality or user expectations.
Patch guidance
Check the official Perfmatters plugin repository and the vendor's security advisories for a patched version released after 2.6.4. Apply patches in a test environment first to confirm no breaking changes. If using a managed WordPress hosting platform, verify whether the host provides automated patching for plugins. If a patch is not yet available, implement the configuration-based mitigations listed in the remediation section while awaiting an official fix.
Detection guidance
Monitor web server and WordPress logs for requests containing directory traversal patterns (e.g., '../', '..\', URL-encoded variants like %2e%2e%2f) in the 's' parameter when the Perfmatters plugin is processing requests. If Local Google Fonts is enabled, establish baseline logging for font-serving endpoints and alert on anomalous file path requests. Intrusion detection systems can be configured with rules targeting path traversal attempts against known WordPress plugin endpoints. Consider conducting a file integrity check on configuration files (wp-config.php, plugin settings files) to detect unauthorized reads or modifications.
Why prioritize this
This vulnerability merits immediate attention because it enables unauthenticated, remote read access to sensitive server files with minimal attack complexity. While the conditional trigger requirements reduce exposure scope, the potential for credential theft and downstream compromise is severe. Organizations with Perfmatters installed should quickly audit their plugin configuration to determine if the three prerequisite conditions are met, and those with Local Google Fonts enabled should prioritize patching.
Risk score, explained
The CVSS 3.1 score of 7.5 (HIGH) reflects the vulnerability's network accessibility (AV:N), low attack complexity (AC:L), and lack of authentication requirement (PR:N). No user interaction is needed (UI:N). The impact is high for confidentiality (C:H)—attackers can read arbitrary files—but integrity and availability are not affected (I:N/A:N). The HIGH severity is justified despite the three configuration prerequisites, because those prerequisites are legitimate feature configurations that users may enable for legitimate reasons and do not require specialized setup.
Frequently asked questions
Does this vulnerability affect my WordPress site if I haven't enabled Local Google Fonts?
Unlikely. The Local Google Fonts feature is disabled by default, and the vulnerability requires it to be enabled alongside pretty permalinks and active RSS feed links. If you have not intentionally enabled Local Google Fonts, your exposure is minimal. Check your Perfmatters plugin settings to confirm.
Can I be exploited if I disable pretty permalinks?
No. The vulnerability requires pretty permalinks to be enabled. If you disable them, you eliminate one of the three prerequisite conditions and the vulnerability becomes unexploitable. However, disabling pretty permalinks may affect your site's URL structure and SEO. Patching is the recommended long-term solution.
Is there a public exploit available?
No known public exploit or KEV status exists as of the vulnerability publication date. However, directory traversal attacks are well-understood, and exploitation tooling could emerge quickly. Do not rely on obscurity; update or mitigate as soon as possible.
If I update to a patched version, do I need to audit my server for breach?
Yes. If your site met the three exploitation conditions before patching, assume attackers could have accessed sensitive files. Review your access logs for suspicious requests, rotate any exposed credentials (database passwords, API keys), and conduct a security audit of affected systems.
This analysis is provided for informational purposes and reflects publicly available information as of the publication date. Vendor patch timelines and actual exploitation in the wild may differ from this assessment. Organizations should verify compatibility and test patches in non-production environments before deployment. This explainer does not constitute professional security advice; consult your security team and vendor advisories for decisions specific to your environment. Source: NVD (public-domain), retrieved 2026-08-11. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2016-20076HIGHWordPress Simple-Backup 2.7.11 Unauthenticated File Access & Deletion Vulnerability
- CVE-2016-20081HIGHHB Audio Gallery Lite Path Traversal Vulnerability – Unauthenticated File Download
- CVE-2017-20248HIGHApptha Slider Gallery Path Traversal Vulnerability
- CVE-2017-20250HIGHMac Photo Gallery 3.0 Path Traversal File Download Vulnerability
- CVE-2018-25408HIGHOpen ISES Project Path Traversal Vulnerability (High Severity)
- CVE-2024-32729HIGHPath Traversal in QuantumCloud Conversational Forms for ChatBot (CVSS 7.5)
- CVE-2024-40646HIGHVertex Path Traversal Vulnerability – Remote File Access Risk
- CVE-2025-60223HIGHWPBot Pro Arbitrary File Deletion Vulnerability – HIGH Risk Exploit