{"id":"CVE-2026-19224","title":"The Hummingbird Performance  WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the enti…","summary":"The Hummingbird Performance  WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the enti…","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-94"],"published":"2026-09-04","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:15:18.627","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19224","references":[{"url":"https://wpscan.com/vulnerability/443461c5-93c4-49b4-a5c2-057b7afa4ce6/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.0037,"epssPercentile":0.30868,"ingestedAt":"2026-09-08T20:10:03.163Z","slug":"CVE-2026-19224","body":"## Overview\n\nThe Hummingbird Performance  WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}