SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-19224

HIGH · CVSS 7.2 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Hummingbird Performance plugin for WordPress prior to version 3.21.2 is vulnerable due to insufficient restrictions on network-wide settings, enabling an administrator of any individual site within a multisite network to execute arbitrary code across the entire network. This flaw poses a significant risk as it could lead to unauthorized access and control over all sites in the network. WordPress multisite administrators should prioritize updating to the latest version to mitigate this security risk.

CVE
CVE-2026-19224
Severity
HIGH
CVSS
7.2
EPSS
0.37%
WordPress

Original NVD Description

The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.