CVE Vulnerabilities

CVE-2025-14437

Insertion of Sensitive Information into Log File

Published: Dec 18, 2025 | Modified: Dec 18, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the request function. This makes it possible for unauthenticated attackers to extract sensitive data including Cloudflare API credentials.

Weakness

The product writes sensitive information to a log file.

Potential Mitigations

References