{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awpmudevhummingbirdwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wpmudev:hummingbird:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-83627"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Hummingbird (\u003c= 3.21.0)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","rce","vulnerability"],"_cs_type":"advisory","_cs_vendors":["WPMU DEV"],"content_html":"\u003cp\u003eThe Hummingbird - Speed Optimization, Caching, Minify, Compress \u0026amp; CDN plugin for WordPress (versions \u0026lt;= 3.21.0) is vulnerable to unauthenticated remote code execution (RCE). The vulnerability originates in the log_msg() function within the core/modules/class-page-cache.php file. The plugin maintains a debug log at 'wp-content/wphb-logs/page-caching-log.php', which is designed to prevent direct execution via a '\u003c?php die(); ?\u003e' header. However, due to a namespace resolution error in the class_exists() check, the header is omitted when the log is generated during a front-end request.\u003c/p\u003e\n\u003cp\u003eAn attacker can leverage this flaw by sending a crafted HTTP request containing cookies prefixed with 'wphb_cache_'. Because these cookies are written to the debug log without sanitization, an attacker can inject arbitrary PHP code. Once the log file is updated or rotated - either through manual action, cache flushing, or the plugin's automatic daily cron - the malicious payload becomes active. A subsequent direct request to the log file triggers execution of the injected code, granting the attacker full remote code execution capabilities.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify WordPress sites running the vulnerable Hummingbird plugin.\u003c/li\u003e\n\u003cli\u003eAttacker verifies the target has the 'Page Caching' debug log feature enabled.\u003c/li\u003e\n\u003cli\u003eAttacker sends an HTTP request to the target site with a malicious payload embedded in a cookie named with the 'wphb_cache_' prefix.\u003c/li\u003e\n\u003cli\u003eThe log_msg() function processes the request and writes the unauthenticated/unsanitized cookie content directly into the 'wp-content/wphb-logs/page-caching-log.php' file.\u003c/li\u003e\n\u003cli\u003eThe plugin log-rotation or cache flush process executes, causing the log file to lose its protective PHP header due to the namespace resolution error.\u003c/li\u003e\n\u003cli\u003eAttacker sends a direct HTTP request to 'wp-content/wphb-logs/page-caching-log.php'.\u003c/li\u003e\n\u003cli\u003eThe web server executes the injected PHP code contained within the log file.\u003c/li\u003e\n\u003cli\u003eAttacker achieves remote command execution on the underlying server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary PHP code on the server hosting the WordPress instance. This can lead to full site takeover, data exfiltration, internal network lateral movement, or complete compromise of the web server infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate update of the Hummingbird plugin to version 3.21.1 or later to remediate CVE-2026-83627. If an immediate update is not possible, disable the 'Page Caching' debug log feature and ensure the 'wp-content/wphb-logs/' directory is restricted from direct web access via web server configuration (e.g., denying access in .htaccess or Nginx configuration files). Implement the webserver-based detection rule below to identify exploitation attempts targeting the log file endpoint.\u003c/p\u003e\n","date_modified":"2026-09-05T07:29:59Z","date_published":"2026-09-05T07:29:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-hummingbird-rce/","summary":"An unauthenticated remote code execution vulnerability in the Hummingbird WordPress plugin allows attackers to inject and execute arbitrary PHP code via unsanitized cookie headers in the debug log.","title":"CVE-2026-83627: Unauthenticated RCE in Hummingbird WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-hummingbird-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wpmudev:hummingbird:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}