/Vulnerability Library

WordPress Hummingbird <= 3.18.0 - Sensitive Information Exposure via Log File

CVE-2025-14437
Verified

Description

Hummingbird Performance WordPress plugin <= 3.18.0 contains a sensitive information exposure caused by improper handling in the 'request' function, letting unauthenticated attackers extract sensitive data including Cloudflare API credentials, exploit requires no authentication.

Severity

High

CVSS Score

7.5

Exploit Probability

2%

Affected Product

hummingbird-performance

Published Date

March 26, 2026

Template Author

pussycat0x

CVE-2025-14437.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2025-14437
CWE ID:
cwe-532

References

https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hummingbird-performance/hummingbird-3180-unauthenticated-sensitive-information-exposure-via-log-fileshttps://wpscan.com/vulnerability/cve-2025-14437https://plugins.trac.wordpress.org/changeset/3421187/hummingbird-performance

Remediation Steps

Update to the latest version beyond 3.18.0.