Summary
CVE-2026-13251 is a high-severity unauthenticated directory traversal vulnerability affecting the Perfmatters WordPress plugin in all versions up to and including 2.6.4. By supplying a crafted value in the 's' parameter, a remote unauthenticated attacker can read the contents of arbitrary files on the server, potentially exposing sensitive data such as configuration files and credentials. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) and requires no authentication or user interaction to exploit.
Technical details
- Root cause: Improper path validation in the
's'parameter within theFonts.phpcomponent (line 131) of the Perfmatters plugin. The input is not sufficiently sanitized before being used to construct a file path, allowing directory traversal sequences to escape the intended directory boundary. - Trigger conditions (all three must be met): (1) The Local Google Fonts feature is enabled (disabled by default); (2) Pretty permalinks are active on the WordPress installation; (3) RSS feed links are enabled in the Perfmatters plugin settings.
- Attack vector: Unauthenticated network attacker sends a crafted HTTP request containing path traversal sequences in the
's'parameter to a vulnerable WordPress endpoint. - Impact: Arbitrary read of files accessible to the web server process — including sensitive server-side files such as
wp-config.php, environment files, or system files (e.g.,/etc/passwd). Confidentiality impact is rated High (C:H); Integrity and Availability are unaffected (I:N/A:N).
Affected software
- Perfmatters WordPress Plugin — all versions up to and including 2.6.4
Severity
- CVSS v3.1 Base Score: 7.5 (High)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate — update now: Upgrade the Perfmatters plugin to version 2.6.5 (released June 30, 2026), which introduces domain verification and content-type validation for the Local Google Fonts feature, addressing the traversal path.
- If immediate patching is not possible:
- Disable the Local Google Fonts feature within the Perfmatters plugin settings — this removes the precondition required for exploitation.
- Apply Web Application Firewall (WAF) rules to block requests containing directory traversal sequences (e.g.,
../) in query parameters targeting WordPress endpoints. - Restrict web server file-read permissions to the minimum required scope to limit the files an attacker could access if the vulnerability were triggered.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

