Impact
The Perfmatters plugin for WordPress, versions 2.6.4 and earlier, contains a directory traversal flaw (CWE‑22) that is triggered by a malicious value in the 's' query parameter; when Local Google Fonts is enabled, pretty permalinks are active, and RSS feed links are enabled, the plugin incorrectly reads the 's' parameter and allows an unauthenticated attacker to retrieve the contents of any file the web server process can access, potentially exposing configuration files, credentials, or source code, compromising confidentiality.
Affected Systems
All WordPress installations using the Perfmatters plugin 2.6.4 or earlier with Local Google Fonts enabled, pretty permalinks active, and RSS feed links enabled are affected.
Risk and Exploitability
The CVSS score of 7.5 marks this as a high‑severity remote read vulnerability that requires no authentication. The EPSS score of less than 1 % indicates that exploitation attempts are currently rare, and the flaw is not listed in the CISA KEV catalog. An attacker can remotely exploit this by crafting a URL that includes a malicious 's' parameter, which the server processes when the stated configuration prerequisites are met, thereby returning the contents of arbitrary files.
OpenCVE Enrichment