Hummingbird Performance WordPress 插件在 3.21.2 版本之前,未将一项影响整个网络的设置限制为仅网络管理员可操作,导致多站点网络中任意单个站点的管理员能够在整个网络范围内执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Hummingbird Performance | 3.15.0 ~ 3.21.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84146 | Xpro Elementor Addons < 1.7.8 - Unauthenticated Draft/Private Product Disclosure via Quick | |
| CVE-2026-84066 | Directorist < 8.9 - Subscriber+ Arbitrary Post Meta Write via atbdp_post_attachment_upload | |
| CVE-2026-82193 | WPvivid Backup & Migration < 0.9.134 - Admin+ File Write Outside the Backup Directory via | |
| CVE-2026-82194 | WPvivid Backup & Migration < 0.9.134 - Admin+ Arbitrary File Deletion via Path Traversal | |
| CVE-2026-82186 | WPLP Cookie Consent < 4.4.2 - Admin+ SQLi via 'offset' Parameter | |
| CVE-2026-81347 | Frontend Admin by DynamiApps < 3.29.13 - Unauthenticated .htaccess and index.php Deletion | |
| CVE-2026-80438 | Ninja Forms 3.14.0 - 3.15.1 - Authenticated Arbitrary Post Modification and Sensitive Info | |
| CVE-2026-79631 | WPFunnels < 3.13.0 - Unauthenticated Order and Opt-In PII Disclosure via Web-Accessible Lo | |
| CVE-2026-79632 | WPFunnels < 3.13.0 - Unauthenticated Arbitrary Recipient Email Sending via wpfnl_shortcode | |
| CVE-2026-74853 | Pods < 3.3.9.2 - Author+ Arbitrary File Read via Shortcode Display Callback | |
| CVE-2026-16281 | Classified Listing < 6.1.1 - Subscriber+ Arbitrary Attachment Deletion and Listing Image T | |
| CVE-2026-17517 | Content Views < 4.5.1.2 - Unauthenticated Non-Public Post Content Disclosure via Views Sta | |
| CVE-2026-79630 | WPFunnels < 3.13.0 - Unauthenticated Price Manipulation via Order Bump Product ID Substitu | |
| CVE-2025-15691 | WPFunnels < 3.13.0 - Unauthenticated User Registration via Opt-in Forms |
No comments yet