CVE-2026-3881 PUBLISHED

Performance Monitor <= 1.0.6 - Unauthenticated Blind SSRF

Assigner: WPScan
Reserved: 10.03.2026 Published: 31.03.2026 Updated: 31.03.2026

The Performance Monitor WordPress plugin through 1.0.6 does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attacks

Product Status

Vendor Unknown
Product Performance Monitor
Versions Default: unknown
  • affected from 0 to 1.0.6 (incl.)

Credits

  • Afshin Shekaari finder
  • WPScan coordinator

References

Problem Types

  • CWE-918 Server-Side Request Forgery (SSRF) CWE