
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14437 is a sensitive information exposure vulnerability in the Hummingbird Performance plugin for WordPress, affecting all versions up to and including 3.18.0. The flaw exists in the plugin's request function and allows unauthenticated attackers to extract sensitive data, including Cloudflare API credentials. It was published on December 18, 2025, and assigned a CVSS v3.1 base score of 7.5 (High) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File), where the plugin's request function improperly handles or exposes sensitive configuration data such as Cloudflare API credentials. The vulnerability is network-accessible, requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable by any remote attacker. A patch was committed to the WordPress plugin repository (changeset 3421187), and Nuclei detection templates have been added to the ProjectDiscovery repository to facilitate automated scanning (Wordfence, Plugin Changeset, Nuclei Templates).
Successful exploitation allows unauthenticated remote attackers to extract Cloudflare API credentials and potentially other sensitive configuration data stored or processed by the plugin. Exposure of Cloudflare API keys could enable attackers to manipulate DNS records, disable DDoS protection, intercept traffic, or pivot to further attacks against the site's infrastructure. The confidentiality impact is rated High, with no direct integrity or availability impact from the vulnerability itself, though secondary abuse of stolen credentials could affect all three (Wordfence, Red Hat CVE).
No public exploit code or in-the-wild exploitation has been confirmed as of the available data. The EPSS score is approximately 0.058%, indicating a low current probability of exploitation in the wild. Nuclei templates for automated detection of this vulnerability were added to the ProjectDiscovery repository in mid-2026, which may lower the barrier for opportunistic scanning (Nuclei Templates, Wordfence). The vulnerability is not listed in the CISA KEV catalog.
request function endpoint or the relevant REST API/AJAX handler exposed by the plugin.request function; repeated requests from single IPs probing plugin-related REST API or AJAX endpoints.Update the Hummingbird Performance plugin to version 3.18.1 or later, which contains the fix as reflected in the plugin repository changeset 3421187. No configuration-based workaround is documented; upgrading is the recommended and primary remediation. Site administrators should also rotate any Cloudflare API credentials that may have been exposed while running a vulnerable version (Plugin Changeset, Wordfence).
Wordfence included CVE-2025-14437 in its weekly WordPress vulnerability report covering December 15, 2025 to January 4, 2026, and Sucuri referenced it in its December 2025 vulnerability patch roundup (Wordfence Blog, Sucuri Blog). Community discussion was observed on Bluesky and security aggregator platforms, though no major controversy or widespread alarm was noted given the availability of a patch at disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."