Hummingbird <= 3.18.0 - Unauthenticated Sensitive Information Exposure via Log File
58Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actcvss 7.5epss 2.0%
de la publicación al arma
Publicada en NVD18 dic
VulnCheck+104d
probabilidad de explotación
2.0%top 21% de las CVE
explotación observada
síVulnCheck
The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function. This makes it possible for unauthenticated attackers to extract sensitive data including Cloudflare API credentials.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N