CRITICAL
9.8 CVE-2026-83627 Published 5 Sept 2026
WordPress Hummingbird Plugin RCE Bug
Worried this affects your website?
The Hummingbird plugin for WordPress is vulnerable to Remote Code Execution (RCE) in versions up to 3.21.0.
An unauthenticated attacker can write and execute arbitrary PHP code by exploiting a flaw in the page-cache debug log file.
Impact: Full remote code execution. Affected Versions: All versions up to and including 3.21.0.
Reference: CVE-2026-83627 on NVD
← Back to Security News