CVE-2025-14437
🟡 Monitoruj
Wtyczka Hummingbird Performance dla WordPressa umożliwia wyciek wrażliwych danych, w tym poświadczeń API Cloudflare.
CVSS
7.5
EPSS
1.9%
Exploit
none
Vendor
Opis źródłowy (NVD)
The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function. This makes it possible for unauthenticated attackers to extract sensitive data including Cloudflare API credentials.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 1.9% |
| Opublikowano (NVD) | 2025-12-18 13:15:47 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-01 16:10:00 UTC |