WordPress Hummingbird plugin <= 3.9.1 - Broken Access Control vulnerability
CVE-2024-43118
8.8HIGH
What is CVE-2024-43118?
A missing authorization issue has been identified in the WPMU DEV Hummingbird plugin, allowing attackers to exploit incorrectly configured access control security levels. This vulnerability impacts all versions of Hummingbird up to and including 3.9.1, potentially exposing sensitive functionalities and data to unauthorized users. Proper security configurations are essential to mitigate this risk and protect WordPress installations.
Affected Version(s)
Hummingbird <= 3.9.1