Skip to main content
Loading…
    CVE-2026-1648 — The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.6. This is due to insufficient validation of the 'url' param — CVE Database · The Intelligence Room