The Performance Monitor WordPress plugin through 1.0.6 does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attacks
CVE-2026-3881
NONE
Updated Mar 31, 2026
WordPress
CVE Details
CVE ID
CVE-2026-3881
Published Date
Mar 31, 2026
Vendor
WordPress
Severity
NONE
Impact
Minimal impact
Source
View Advisory