Remote Code Execution Vulnerability in Hummingbird Plugin from WordPress
CVE-2026-83627
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 September 2026
What is CVE-2026-83627?
The Hummingbird plugin for WordPress suffers from a Remote Code Execution vulnerability due to improper protection of its debug log file. The log file, created during front-end requests, lacks necessary safeguards, allowing unauthenticated attackers to inject and execute arbitrary PHP code. This issue arises from the flawed implementation of the log_msg() function, which fails to enforce the protection measures typically necessary to keep such logs secure. If certain caching and logging settings are enabled, attackers can exploit this vulnerability with minimal effort, posing a severe risk to affected installations. Users of the plugin are strongly advised to update to the latest version and review their security settings to mitigate potential threats.
Affected Version(s)
Hummingbird Performance β Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN 0 <= 3.21.0