Detects the Performance Monitor WordPress plugin before version 1.0.7, where the curl_data REST endpoint (permission_callback: __return_true) passes user-supplied URLs directly to curl_init()/curl_exec() without validation. Unauthenticated attackers can make the server fetch arbitrary URLs including internal services and cloud metadata.
Is your app exploitable through CVE-2026-1648?
Scan your domain free