Junglewise Threat Intelligence

CVE-2026-19224: Hummingbird Performance privilege escalation in network settings

CVE-2026-19224 · Severity: high · CVSS 7.2 · Published 2026-09-04

Vendors: WPMU DEV.

Executive brief

Hummingbird Performance is a popular WordPress plugin that optimizes website speed and performance. A vulnerability in versions before 3.21.2 allows an administrator of any single website on a multisite network to modify network-wide settings and execute arbitrary code across the entire network. This could result in complete compromise of all websites hosted on the affected multisite installation.

Technical details

The plugin fails to properly restrict access to network-wide settings to network administrators only, allowing a regular site administrator to modify these settings. The vulnerability is rooted in inadequate authorization checks on the Hub Connector functionality. An authenticated site administrator on a multisite WordPress network can leverage this to inject and execute arbitrary code across all sites on the network. This is a privilege escalation attack that requires administrative access to at least one site in the multisite network. The fix is available in version 3.21.2 and later.

Affected products

  • WPMU DEV Hummingbird Performance before 3.21.2

Timeline

  • 2026-09-02: disclosed
  • 2026-09-04: patched: Fixed in version 3.21.2

References