PoC Index

CVE-2025-14437

HIGH 7.5EPSS 1.9%

The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function. This makes it possible for unauthenticated attackers to extract sensitive data including Cloudflare API credentials.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.94% chance of exploitation in the next 30 days, 79th percentile
Nuclei
high · CWE-532
Published
2025-12-18
Updated
2026-04-08

Nuclei templates (1)

References

Related