stemshop.top
Critical Remote Code Execution Vulnerability in Hummingbird Plugin for WordPress
Article Content
The Hummingbird plugin for WordPress, versions up to and including 3.21.0, is vulnerable to Remote Code Execution (RCE) due to a flaw in the log_msg() function. This vulnerability allows unauthenticated attackers to inject arbitrary PHP code into a web-accessible log file (wp-content/wphb-logs/page-caching-log.php) without proper sanitization. Exploitation requires the Page Caching with Debug Log option to be enabled, which is not the default setting. The vulnerability arises from a namespace resolution issue that omits a protective header, permitting attackers to execute crafted cookies. The CVE-2026-83627 has been assigned a critical CVSS score of 9.8. Currently, there is no public proof-of-concept or confirmed exploitation reported. Users are advised to update the plugin or disable the vulnerable feature immediately. The vulnerability was disclosed on September 5, 2026.
Key Points: • Hummingbird plugin versions up to 3.21.0 are critically vulnerable to RCE. • Exploitation requires specific conditions, including enabled Debug Log option. • No public proof-of-concept or confirmed exploitation has been reported yet.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.