- Description
- The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function. This makes it possible for unauthenticated attackers to extract sensitive data including Cloudflare API credentials.
- Source
- security@wordfence.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
- security@wordfence.com
- CWE-532
- Hype score
- Not currently trending
๐จ [HIGH] Active exploitation detected: CVE-2025-14437 Exploit in the wild confirmed for CVE-2025-14437 (CVSS null). The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information ... ๐ https://t.co/RZBhpWnHFz #ZeroDay #ExploitInWild #CyberSecurity
@ctiwatchcloud
14 Apr 2026
146 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
๐จ CVE-2025-14437 - high ๐จ WordPress Hummingbird <= 3.18.0 - Sensitive Information Exposure via Log File > Hummingbird Performance WordPress plugin <= 3.18.0 contains a sensitive information e... ๐พ https://t.co/EV6IIAJLSF @pdnuclei #NucleiTe...
@pdnuclei_bot
30 Mar 2026
197 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes