CVE-2025-14437Disclosure

LOWCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function. This makes it possible for unauthenticated attackers to extract sensitive data including Cloudflare API credentials.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-532

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-30); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-30: 1Mentions · 2026-04-14: 1Active Exploitation · 2026-04-14: 1Technical Details · 2026-03-30: 103-3004-14
Signal classification2 categories
Disclosure
150.0%
Active Exploitation
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-301
Disclosure1
2026-04-141
Active Exploitation1
Full discourse2 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-14437 - high 🚨 WordPress Hummingbird <= 3.18.0 - Sensitive Information Exposure via Log File > Hummingbird Performance WordPress plugin <= 3.18.0 contains a sensitive information e... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-14437 @pdnuclei #NucleiTe...

    Post summary

    The tweet announces CVE-2025-14437 as a high-severity vulnerability in WordPress Hummingbird (≤3.18.0), exposing sensitive information via log files, and provides a reference link but no exploit or patch details.

    01010275
    905 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2025-14437 Exploit in the wild confirmed for CVE-2025-14437 (CVSS null). The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information ... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    CVE-2025-14437 is reported as being actively exploited in the wild against the Hummingbird Performance WordPress plugin, with an alert linked to ctiwatch, but no technical or patch details are disclosed.

    00000261
    5.6K followersView on X

Explore more