Skip to content

Known CVE

WordPress Hummingbird <= 3.18.0 - Sensitive Information Exposure via Log File

Hummingbird Performance WordPress plugin <= 3.18.0 contains a sensitive information exposure caused by improper handling in the 'request' function, letting unauthenticated attackers extract sensitive data including Cloudflare API credentials, exploit requires no authentication.

CVE-2025-14437

High2025CVSS 7.5CWE-532

cve2025 · wordpress · wp-plugin · hummingbird · exposure · cloudflare · wpmudev · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website