plugin

Hummingbird Performance Vulnerabilities

12 known security issues reported for the Hummingbird Performance WordPress plugin. Most recent disclosed Dec 18, 2025.

1 high 5 medium

Running Hummingbird Performance on your site? Check whether your installed version is affected.

Scan your site free

Hummingbird Performance &#8211; Cache &amp; Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN [hummingbird-performance] < 3.18.1

unknown

[en] The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function. This makes it possible for unauthenticated attackers to extract sensitive data including Cloudflare API credentials.

Affected:
up to 3.18.1
Fixed in:
3.18.1
Disclosed:
Dec 18, 2025

CVE-2025-14437 on NVD →

Hummingbird <= 3.18.0 - Unauthenticated Sensitive Information Exposure via Log File

high

The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function. This makes it possible for unauthenticated attackers to extract sensitive data including Cloudflare API credentials.

CVSS:
7.5
Affected:
up to 3.18.0
Fixed in:
3.18.1
Disclosed:
Dec 17, 2025

CVE-2025-14437 on NVD →

Hummingbird Performance &#8211; Cache &amp; Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN [hummingbird-performance] < 3.9.2

unknown

[en] Missing Authorization vulnerability in WPMU DEV Hummingbird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hummingbird: from n/a through 3.9.1.

Affected:
up to 3.9.2
Fixed in:
3.9.2
Disclosed:
Nov 1, 2024

CVE-2024-43118 on NVD →

Hummingbird Performance &#8211; Cache &amp; Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN [hummingbird-performance] < 3.9.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV Hummingbird.This issue affects Hummingbird: from n/a through 3.9.1.

Affected:
up to 3.9.2
Fixed in:
3.9.2
Disclosed:
Aug 26, 2024

CVE-2024-43117 on NVD →

Hummingbird <= 3.9.1 - Cross-Site Request Forgery

medium

The Hummingbird plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.9.1. This is due to missing or incorrect nonce validation on the on_load and maybe_clear_all_cache functions. This makes it possible for unauthenticated attackers to update settings and clear cache via a...

CVSS:
4.3
Affected:
up to 3.9.1
Fixed in:
3.9.2
Disclosed:
Aug 7, 2024

CVE-2024-43117 on NVD →

Hummingbird <= 3.9.1 - Missing Authorization

medium

The Hummingbird plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clear_module_cache() function in versions up to, and including, 3.9.1. This makes it possible for authenticated attackers, with contributor-level access and above, to clear module cache.

CVSS:
4.3
Affected:
up to 3.9.1
Fixed in:
3.9.2
Disclosed:
Aug 7, 2024

CVE-2024-43118 on NVD →

Hummingbird Performance &#8211; Cache &amp; Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN [hummingbird-performance] < 3.7.4

unknown

[en] Missing Authorization vulnerability in WPMU DEV Hummingbird.This issue affects Hummingbird: from n/a through 3.7.3.

Affected:
up to 3.7.4
Fixed in:
3.7.4
Disclosed:
Jun 9, 2024

CVE-2024-32792 on NVD →

Hummingbird <= 3.7.3 - Missing Authorization

medium

The Hummingbird plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the /admin/class-ajax.php file in versions up to, and including, 3.7.3. This makes it possible for unauthenticated attackers to perform unauthorized actions like clearing cache.

CVSS:
5.3
Affected:
up to 3.7.3
Fixed in:
3.7.4
Disclosed:
Apr 22, 2024

CVE-2024-32792 on NVD →

Hummingbird Performance &#8211; Cache &amp; Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN [hummingbird-performance] < 3.4.2

unknown

[en] The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.

Affected:
up to 3.4.2
Fixed in:
3.4.2
Disclosed:
Apr 10, 2023

CVE-2023-1478 on NVD →

Hummingbird <= 3.4.1 - Unauthenticated Path Traversal

medium

The Hummingbird plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 3.4.1 via the page cache module, which doesn't validate file paths prior to saving them. This makes it possible for unauthenticated attackers to enumerate file directories, crash to server by sending cache files to an...

CVSS:
5.3
Affected:
up to 3.4.1
Fixed in:
3.4.2
Disclosed:
Mar 20, 2023

CVE-2023-1478 on NVD →

Hummingbird Performance &#8211; Cache &amp; Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN [hummingbird-performance] < 3.3.2

unknown

[en] The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privilege users, such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Affected:
up to 3.3.2
Fixed in:
3.3.2
Disclosed:
Apr 18, 2022

CVE-2022-0994 on NVD →

Hummingbird <= 3.3.1 - Admin+ Stored Cross-Site Scripting

medium

The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privilege users, such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVSS:
5.5
Affected:
up to 3.3.2
Fixed in:
3.3.2
Disclosed:
Mar 23, 2022

CVE-2022-0994 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database