Impact
The Perfmatters WordPress plugin contains a directory traversal flaw (CWE-22) that allows anyone with web access to read files on the server. The vulnerability triggered by a specially crafted value of the 's' query parameter, which the plugin passes to a file‑loading routine without proper sanitisation. An attacker can obtain any file readable by the web process, potentially exposing configuration data, credentials, or code. This flaw directly undermines the confidentiality of the site and can aid further attacks such as code execution if the attacker can read source files or identify weaknesses.
Affected Systems
All installations of the Perfmatters plugin for WordPress with a version of 2.6.4 or earlier, that have the Local Google Fonts feature enabled, pretty permalinks active, and RSS feed links turned on, are affected. WordPress sites that meet these preconditions can be targeted through a crafted URL containing the malicious 's' parameter. The flaw is not limited to a specific environment or host, as it relies solely on plugin configuration and request handling.
Risk and Exploitability
The CVSS score of 7.5 reflects a high severity vulnerability that offers remote read access without authentication. The EPSS score of less than 1% indicates that exploitation attempts are currently brief, although the flaw can be triggered from any visitor, so it could still be abused. The issue is not listed in CISA’s KEV catalog. An attacker request to the site with a malicious 's' parameter while the relevant plugin features are enabled the specified preconditions or applying the vendor’s patch curtails the attack surface entirely.
OpenCVE Enrichment