CVE-2026-83627
Hummingbird WordPress Plugin Remote Code Execution via Debug Log.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A vulnerability in the Hummingbird WordPress plugin could allow unauthenticated attackers to execute arbitrary PHP code. This occurs because a security check is bypassed, allowing malicious code to be written into a web-accessible log file if specific debug logging settings are enabled. This could lead to a full websit