What the vulnerability does
01Description
Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.7.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.7.3.
Explanation of Vulnerability in Simple Terms
The Hummingbird WordPress plugin through version 3.7.3 lacks proper authorization checks on certain administrative functions. A logged-in user with low privileges can modify site settings they should not have access to. The vulnerability requires an active WordPress account but does not require administrator rights. Site owners should update to a version newer than 3.7.3.
What an attacker can do
Modify site settings or configuration without proper authorization.
Potential impact on your site
Unauthorized users can alter Hummingbird settings, potentially affecting site performance or security configurations.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities