CVE-2026-19224

Hummingbird · Hummingbird Performance

The Hummingbird Performance WordPress plugin allows site-level administrators in a multisite network to execute arbitrary code across the entire network by failing to restrict sensitive settings.

Executive summary

A critical authorization vulnerability in the Hummingbird Performance plugin allows authenticated site administrators to achieve remote code execution across an entire WordPress multisite network.

Vulnerability

This flaw involves improper control of code generation (CWE-94) where the plugin fails to perform necessary capability checks on network-wide settings. While the attack requires administrative privileges on a single sub-site, it permits an attacker to escalate their impact to the entire multisite environment.

Business impact

Successful exploitation grants an attacker the ability to execute arbitrary code, which can lead to complete compromise of the WordPress multisite environment. With a CVSS score of 7.2, this vulnerability poses a significant risk to data integrity and system availability, potentially allowing unauthorized access to sensitive information across every site hosted on the network.

Remediation

Immediate Action: Update the Hummingbird Performance plugin to version 3.21.2 or later immediately to resolve the improper access control.

Proactive Monitoring: Review WordPress multisite audit logs for unusual administrative activity or unauthorized modifications to network-wide plugin settings.

Compensating Controls: If immediate patching is not feasible, consider temporarily deactivating the plugin on the multisite network or restricting administrative access to the specific settings page via WAF rules.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for full network compromise, administrators must prioritize updating the Hummingbird Performance plugin to version 3.21.2. The risk of lateral movement from a single sub-site to the entire network makes this update essential for maintaining the security posture of the WordPress multisite installation.

History

CVE Brief tracked this CVE 4 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.2 (3.1)
  4. Analyst report written

Sources

Originally found and disclosed by Jakub Herman, with WPScan (coordinator), per the CVE Program record.