CVE-2026-1648Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.6. This is due to insufficient validation of the 'url' parameter in the '/wp-json/performance-monitor/v1/curl_data' REST API endpoint. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations, including internal services, via the Gopher protocol and other dangerous protocols. This can be exploited to achieve Remote Code Execution by chaining with services like Redis.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-21: 2Technical Details · 2026-03-21: 103-21
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-1648 - qrolic - Performance Monitor - https://www.redpacketsecurity.com/cve-alert-cve-2026-1648-qrolic-performance-monitor/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-1648 #qrolic #performance-monitor

    Post summary

    A brief alert linking to a Red Packet Security page for CVE-2026-1648 with no detailed technical or actionable information.

    0000055
    3.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1648 The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.6. This is due to insufficient valid… https://www.cve.org/CVERecord?id=CVE-2026-1648

    Post summary

    The post announces that the WordPress Performance Monitor plugin is vulnerable to SSRF up through version 1.0.6, providing technical details but no PoC, exploit, fix, or evidence of active attacks.

    0000057
    56.8K followersView on X

Explore more