{"id":"CVE-2026-19224","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-19224","summary":"The Hummingbird Performance  WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite…","details":"The Hummingbird Performance  WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.","published":"2026-09-04T07:17:08.937","modified":"2026-09-04T07:17:08.937","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://wpscan.com/vulnerability/443461c5-93c4-49b4-a5c2-057b7afa4ce6/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-04T07:17:08.937"}}