Hummingbird <= 3.18.0 - Unauthenticated Sensitive Information Exposure via Log File
2025-12-17 23:41
ISMAILSHADOWStrategic Overview
StatusPatched in 3.18.1
Affected PluginHummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN
Affected Version
<= 3.18.0CVSS7.5High
CVE
CVE-2025-14437Vulnerability Overview
The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function. This makes it possible for unauthenticated attackers to extract sensitive data including Cloudflare API credentials.
Technical Analysis
REMEDIATION: Update to version 3.18.1, or a newer patched version --- IDENTIFIER: CWE-532 (Insertion of Sensitive Information into Log File) The product writes sensitive information to a log file.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C