Extension WordPress

Vulnérabilités Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN

Cette page rassemble les failles publiées pour Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN, leurs plages de versions affectées et les correctifs signalés dans la base locale.

6Vulnérabilités
0Critiques
6Avec correctif
7,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN

6 fiches

CVE-2025-14437 Élevée · 7,5
Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN

Hummingbird <= 3.18.0 – Unauthenticated Sensitive Information Exposure via Log File

The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function. This makes it possible for unauthenticated attackers to extract sensitive data including Cloudflare API…

Versions affectées

*-3.18.0

Correctif

3.18.1

Publication

18/12/2025

CVE-2024-43117 Moyenne · 4,3
Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN

Hummingbird <= 3.9.1 – Cross-Site Request Forgery

The Hummingbird plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.9.1. This is due to missing or incorrect nonce validation on the on_load and maybe_clear_all_cache functions. This makes it possible for…

Versions affectées

*-3.9.1

Correctif

3.9.2

Publication

07/08/2024

CVE-2024-43118 Moyenne · 4,3
Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN

Hummingbird <= 3.9.1 – Missing Authorization

The Hummingbird plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clear_module_cache() function in versions up to, and including, 3.9.1. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-3.9.1

Correctif

3.9.2

Publication

07/08/2024

CVE-2024-32792 Moyenne · 5,3
Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN

Hummingbird <= 3.7.3 – Missing Authorization

The Hummingbird plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the /admin/class-ajax.php file in versions up to, and including, 3.7.3. This makes it possible for unauthenticated attackers to…

Versions affectées

*-3.7.3

Correctif

3.7.4

Publication

22/04/2024

CVE-2023-1478 Moyenne · 5,3
Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN

Hummingbird <= 3.4.1 – Unauthenticated Path Traversal

The Hummingbird plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 3.4.1 via the page cache module, which doesn't validate file paths prior to saving them. This makes it possible for unauthenticated attackers…

Versions affectées

*-3.4.1

Correctif

3.4.2

Publication

20/03/2023

CVE-2022-0994 Moyenne · 5,5
Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN

Hummingbird <= 3.3.1 – Admin+ Stored Cross-Site Scripting

The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privilege users, such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Versions affectées

[*, 3.3.2)

Correctif

3.3.2

Publication

23/03/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités