Critical Remote Code Execution Vulnerability in Hummingbird Plugin for WordPress

Critical Remote Code Execution Vulnerability in Hummingbird Plugin for WordPress

First seen 5 Sep 2026, 16:14 UTC FeedlyNvd.Niststemshop.topeuvd.enisa.europa.eu 70.5

Article Content

Browse articles
ThreatCluster

The Hummingbird plugin for WordPress, versions up to and including 3.21.0, is vulnerable to Remote Code Execution (RCE) due to a flaw in the log_msg() function. This vulnerability allows unauthenticated attackers to inject arbitrary PHP code into a web-accessible log file (wp-content/wphb-logs/page-caching-log.php) without proper sanitization. Exploitation requires the Page Caching with Debug Log option to be enabled, which is not the default setting. The vulnerability arises from a namespace resolution issue that omits a protective header, permitting attackers to execute crafted cookies. The CVE-2026-83627 has been assigned a critical CVSS score of 9.8. Currently, there is no public proof-of-concept or confirmed exploitation reported. Users are advised to update the plugin or disable the vulnerable feature immediately. The vulnerability was disclosed on September 5, 2026.

Key Points: • Hummingbird plugin versions up to 3.21.0 are critically vulnerable to RCE. • Exploitation requires specific conditions, including enabled Debug Log option. • No public proof-of-concept or confirmed exploitation has been reported yet.

Ask AI about this cluster

Timeline

2026-09-05
CVE-2026-83627 published
The vulnerability in the Hummingbird plugin was officially disclosed, allowing RCE through log file exploitation.
Nvd.Nist
2026-09-05
Critical CVSS score assigned
CVE-2026-83627 received a CVSS base score of 9.8, indicating a critical vulnerability.
Feedly
2026-09-05
Security advisory released
Advisories recommend updating the Hummingbird plugin or disabling the Debug Log option to mitigate risks.
stemshop.top