What the vulnerability does
01Description
Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.9.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
What the vulnerability does
Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.9.1.
Explanation of Vulnerability in Simple Terms
The Hummingbird WordPress plugin through version 3.9.1 lacks proper authorization checks on certain administrative functions. A logged-in user with low privileges can trigger actions that should be restricted to higher-privilege roles, resulting in a denial-of-service condition. The vulnerability requires valid WordPress credentials but no special interaction from other users.
What an attacker can do
A low-privilege logged-in user can disrupt site availability by triggering restricted administrative functions.
Potential impact on your site
Site availability may be degraded if a low-privilege user account is compromised or misused to trigger denial-of-service actions.
Conditions required to exploit
Attacker must have a valid WordPress user account with low privileges (e.g., Subscriber or Contributor role).
Key dates
External resources
Related vulnerabilities