
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3881 is an unauthenticated Blind Server-Side Request Forgery (SSRF) vulnerability in the Performance Monitor WordPress plugin through version 1.0.6. The plugin fails to validate a user-supplied URL parameter before making an HTTP request to it, enabling unauthenticated attackers to forge server-side requests. It was publicly disclosed on March 10, 2026, and published to the NVD on March 31, 2026. The vulnerability carries a CVSS v3.1 base score of 5.8 (Medium) (WPScan, GitHub Advisory).
The root cause is classified as CWE-918 (Server-Side Request Forgery), where the plugin's REST API endpoint accepts a url parameter and passes it directly to an HTTP request function without any validation or allowlist enforcement. Specifically, the vulnerable endpoint /wp-json/performance-monitor/v1/curl_data?url= accepts arbitrary URLs, allowing an attacker to direct the WordPress server to make requests to internal or external hosts. No authentication is required to reach this endpoint, and exploitation requires only a crafted HTTP GET request. The original researcher and submitter is Afshin Shekaari (WPScan, GitHub Advisory).
Successful exploitation allows unauthenticated attackers to use the WordPress server as a proxy to reach internal network resources, backend services, and cloud metadata endpoints (e.g., AWS IMDSv1) that are not directly accessible from the internet. This can result in information disclosure of internal infrastructure details, potential lateral movement within the hosting environment, and interaction with services such as databases or administrative interfaces. Availability and integrity are not directly impacted, but confidentiality of internal resources is at risk (WPScan, GitHub Advisory).
No public proof-of-concept exploit code beyond the WPScan-published PoC URL has been observed, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.022–0.044%, placing it in the 14th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (WPScan, GitHub Advisory).
/wp-json/performance-monitor/v1/.https://target.com/wp-json/performance-monitor/v1/curl_data?url=http://127.0.0.1/ and observe whether a response is returned, confirming the endpoint is accessible without authentication.http://127.0.0.1:8282, http://192.168.1.1/, http://169.254.169.254/latest/meta-data/) to enumerate internal services or cloud metadata./wp-json/performance-monitor/v1/curl_data with varying url parameters, especially targeting internal addresses or non-standard ports.As of the disclosure date, there is no known fixed version of the Performance Monitor plugin — WPScan lists "No known fix" for this vulnerability. Site administrators should immediately deactivate and remove the Performance Monitor plugin until a patched version is released. As a compensating control, implement firewall or WAF rules to block outbound connections from the WordPress server to internal network ranges and cloud metadata endpoints. Monitor web server logs for suspicious requests to the vulnerable REST API endpoint (WPScan, GitHub Advisory).
The vulnerability was discovered and responsibly submitted by security researcher Afshin Shekaari via WPScan. It received standard automated coverage across CVE aggregation platforms (VulDB, CVEFeed, CIRCL) and was noted on Bluesky by CVE tracking accounts shortly after publication. No significant vendor statements, major media coverage, or notable researcher commentary beyond the initial WPScan disclosure have been identified (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."