All verified exploits

CVE-2026-1648 Performance Monitor Unauthenticated SSRF

Deterministic high WordPress Added cve-verified-cve-2026-1648

Detects the Performance Monitor WordPress plugin before version 1.0.7, where the curl_data REST endpoint (permission_callback: __return_true) passes user-supplied URLs directly to curl_init()/curl_exec() without validation. Unauthenticated attackers can make the server fetch arbitrary URLs including internal services and cloud metadata.

Related WordPress exploits

Is your app exploitable through CVE-2026-1648?

Scan your domain free