Performance Monitor - Unauthenticated Blind SSRF vulnerability
mediumUnauthenticated Blind SSRF vulnerability
- CVSS:
- 5.4
- Affected:
- up to 1.0.6
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2026
plugin
3 known security issues reported for the Performance Monitor WordPress plugin. Most recent disclosed Apr 1, 2026.
Running Performance Monitor on your site? Check whether your installed version is affected.
Scan your site freeUnauthenticated Blind SSRF vulnerability
Unauthenticated Server-Side Request Forgery via 'url' Parameter vulnerability
The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.6. This is due to insufficient validation of the 'url' parameter in the '/wp-json/performance-monitor/v1/curl_data' REST API endpoint. This makes it possible for unauthenticated attackers...
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free