ZeroHour

CVE-2026-19224

large

Site-admin to network-wide RCE in Hummingbird Performance WordPress plugin < 3.21.2

CVSS 3.1
7.2 high
EPSS
<1%p30
Published
()
Modified
AI analysis

Hummingbird Performance, a WordPress optimization plugin, does not restrict a network-wide setting to network administrators on multisite networks, so an administrator of any single site within the network can alter that setting in a way that injects and executes arbitrary code (CWE-94). The attack is triggered over the network with no user interaction and requires only an administrator account on one site in the network — a common delegation on hosting-provider and managed multisite setups. By exploiting it, the single-site administrator gains the ability to run arbitrary code across the entire multisite network, effectively achieving network-administrator-level control over all hosted sites. Any multisite network running Hummingbird Performance before 3.21.2 and granting administrator rights to non-network-admin users is affected; standalone single-site installs are not exposed by this flaw. No public proof-of-concept is known, it is not listed in CISA KEV, and EPSS currently assigns a 0.4% probability of exploitation within 30 days (30th percentile), so no in-the-wild exploitation has been reported.

What to do: Upgrade Hummingbird Performance to version 3.21.2 or later on all multisite networks. Until patched, limit administrator accounts on individual network sites to trusted network admins and check whether any single-site administrator recently changed network-wide settings or introduced unexpected code. Single-site (non-multisite) WordPress installations are not affected by this issue.

Affected
WPMU DEV Hummingbird Performance (WordPress plugin)All versions before 3.21.2 (fixed in 3.21.2)
Estimated exposure
large≈100k+ active plugin installs, with the realistically exploitable subset (multisite networks with delegated single-site admins) likely in the low tens of… — Hummingbird Performance is listed with roughly 100,000+ active installations on WordPress.org, but the flaw only manifests on multisite networks that grant administrator roles to users who are not network administrators, which is a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.

Ecosystems
WordPress
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.