VYPR

Breeze Cache

by WordPress

CVEs (4)

  • CVE-2026-3844CriApr 23, 2026
    risk 0.60cvss 9.8epss 0.28

    The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary…

  • CVE-2026-79713MedSep 18, 2026
    risk 0.42cvss 6.5epss 0.00

    The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have a page rendered under their own request context stored…

  • CVE-2026-79706MedAug 28, 2026
    risk 0.34cvss 5.3epss 0.00

    The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to build the paths of the files it caches, allowing unauthenticated attackers to create files at arbitrary locations on the server, outside the intended cache…

  • CVE-2026-10551MedJul 13, 2026
    risk 0.00cvss 6.1epss 0.00

    The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML…