CVE-2026-19224
largeSite-admin to network-wide RCE in Hummingbird Performance WordPress plugin < 3.21.2
Hummingbird Performance, a WordPress optimization plugin, does not restrict a network-wide setting to network administrators on multisite networks, so an administrator of any single site within the network can alter that setting in a way that injects and executes arbitrary code (CWE-94). The attack is triggered over the network with no user interaction and requires only an administrator account on one site in the network — a common delegation on hosting-provider and managed multisite setups. By exploiting it, the single-site administrator gains the ability to run arbitrary code across the entire multisite network, effectively achieving network-administrator-level control over all hosted sites. Any multisite network running Hummingbird Performance before 3.21.2 and granting administrator rights to non-network-admin users is affected; standalone single-site installs are not exposed by this flaw. No public proof-of-concept is known, it is not listed in CISA KEV, and EPSS currently assigns a 0.4% probability of exploitation within 30 days (30th percentile), so no in-the-wild exploitation has been reported.
What to do: Upgrade Hummingbird Performance to version 3.21.2 or later on all multisite networks. Until patched, limit administrator accounts on individual network sites to trusted network admins and check whether any single-site administrator recently changed network-wide settings or introduced unexpected code. Single-site (non-multisite) WordPress installations are not affected by this issue.
| WPMU DEV Hummingbird Performance (WordPress plugin) | All versions before 3.21.2 (fixed in 3.21.2) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
- Ecosystems
- WordPress
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.