{"error":0,"message":null,"data":{"name":"Breeze Cache","plugin":"breeze","link":"https:\/\/wordpress.org\/plugins\/breeze\/","latest":"1789565280","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"e8efdc2e886f24c6a0bc5a2fefad5c4146fd3fe65ff1d63a382345877a418f5f","name":"Breeze Cache [breeze] < 2.0.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-29444","name":"CVE-2022-29444","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-29444","description":"[en] Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability in Cloudways Breeze plugin <= 2.0.2 on WordPress allows users with a subscriber or higher user role to execute any of the wp_ajax_* actions in the class Breeze_Configuration which includes the ability to change any of the plugin's settings including CDN setting which could be further used for XSS attack.","date":"2022-05-02"},{"id":"e643ecb66c2b09d509998b78bb028e46fe440d8d","name":"WordPress Breeze plugin <= 2.0.2 - Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/breeze\/vulnerability\/wordpress-breeze-plugin-2-0-2-plugin-settings-change-leading-to-cross-site-scripting-xss-vulnerability","description":"Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability discovered by Dave Jong (Patchstack) in WordPress Breeze plugin (versions <= 2.0.2).","date":"2022-05-02"},{"id":"dab64366-a42f-4625-924a-18a83a70addc","name":"wpscan.com","link":"https:\/\/wpscan.com\/vulnerability\/dab64366-a42f-4625-924a-18a83a70addc","description":null,"date":null},{"id":"79f3377f90498591a9dfc8b94da2d40c192088fb","name":"Breeze \u2013 WordPress Cache Plugin <= 2.0.2 - Unprotected AJAX Actions","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/breeze\/breeze-wordpress-cache-plugin-202-unprotected-ajax-actions","description":"Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability in Cloudways Breeze plugin <= 2.0.2 on WordPress allows users with a subscriber or higher user role to execute any of the wp_ajax_* actions in the class Breeze_Configuration which includes the ability to change any of the plugin's settings including CDN setting which could be further used for XSS attack.","date":"2022-05-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6d466c084d0ec509757c9f8c0e1fff35a20670537e6a195688016764d159e029","name":"Breeze Cache [breeze] < 2.0.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9f8d98d070747dc4430a4d5893eedb992d889bf6","name":"Breeze <= 2.0.8 - Cross-Site Request Forgery via import_json_settings","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/breeze\/breeze-208-cross-site-request-forgery-via-import-json-settings","description":"The Breeze plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.8. This is due to missing or incorrect nonce validation on the 'import_json_settings' function. This makes it possible for unauthenticated attackers to import plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2022-09-19"}],"impact":[]},{"uuid":"3b36082975598943abe9a8267b64a5c7ad966d47a6f1d4ddde1c9ded0fd76e32","name":"Breeze Cache [breeze] < 2.1.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-27188","name":"CVE-2024-27188","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-27188","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cloudways Breeze breeze.This issue affects Breeze: from n\/a through <= 2.1.3.","date":"2024-03-27"},{"id":"a1e24c07babc5d2d8b795b7b83ca6f1ad87e7039","name":"WordPress  Breeze Plugin    <= 2.1.3 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/breeze\/vulnerability\/wordpress-breeze-plugin-2-1-3-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Breeze plugin to the latest available version (at least 2.1.4).\nJorge Diaz discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Breeze Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 2.1.4.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"fd45445d9f41cffec31b2d3de80eadf05d8ab9d6","name":"Breeze <= 2.1.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via breeze_api_token","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/breeze\/breeze-213-authenticated-administrator-stored-cross-site-scripting-via-breeze-api-token","description":"The Breeze plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018breeze_api_token\u2019 parameter in versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-03-25"},{"id":"f8e5fcfc-7a61-43d0-98d7-cb7a71e37579","name":"Breeze &lt; 2.1.4 - Admin+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/f8e5fcfc-7a61-43d0-98d7-cb7a71e37579","description":"The plugin does not sanitise and escape its breeze_api_token settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.9","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"5.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"0dfe807ebc1962e90955ef94c4563b8f1c3b721a683a2c4288a1354a11dac3c4","name":"Breeze Cache [breeze] < 2.1.15","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.15","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-50422","name":"CVE-2024-50422","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-50422","description":"[en] Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n\/a through <= 2.1.14.","date":"2024-10-29"},{"id":"f09cc8405bfee722f8949f1e9d472993a8dd8e60","name":"WordPress Breeze Plugin <= 2.1.14 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/breeze\/vulnerability\/wordpress-breeze-plugin-2-1-14-broken-access-control-vulnerability","description":"<p>WordPress Breeze Plugin <= 2.1.14 is vulnerable to Broken Access Control<\/p><p>Software: Breeze<\/p><p>Link: https:\/\/wordpress.org\/plugins\/breeze\/#developers<\/p><p>Affected Version <= 2.1.14<\/p><p>Fixed in version 2.1.15 <\/p>","date":"2024-10-24"},{"id":"312d1f9d4616d7504358b842269dac8a0660238c","name":"Breeze <= 2.1.14 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/breeze\/breeze-2114-missing-authorization","description":"The Breeze plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_to_default() function in versions up to, and including, 2.1.14. This makes it possible for unauthenticated attackers to reset to default settings.","date":"2024-10-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"n","a":"l","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:L","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"none","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"db4a06b603b2ddbccae8517bd4b3b0fed78841c1c2c89c358b1d45ea08325bda","name":"Breeze Cache [breeze] < 2.1.15","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.15","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-50431","name":"CVE-2024-50431","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-50431","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cloudways Breeze breeze allows Stored XSS.This issue affects Breeze: from n\/a through <= 2.1.14.","date":"2024-10-28"},{"id":"8edfc781a2cfe2dc1b3e6666c6d3f6d7a6aa27b6","name":"WordPress Breeze Plugin <= 2.1.14 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/breeze\/vulnerability\/wordpress-breeze-plugin-2-1-14-cross-site-scripting-xss-vulnerability","description":"<p>WordPress Breeze Plugin <= 2.1.14 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Breeze<\/p><p>Link: https:\/\/wordpress.org\/plugins\/breeze\/#developers<\/p><p>Affected Version <= 2.1.14<\/p><p>Fixed in version 2.1.15 <\/p>","date":"2024-10-24"},{"id":"b2098c1cdabaf3d2adb01a021c4dee3f69689437","name":"Breeze <= 2.1.14 - Authenticated (Administrator+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/breeze\/breeze-2114-authenticated-administrator-stored-cross-site-scripting","description":"The Breeze plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-10-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.9","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"5.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"39868f90b6dd8b4d41dc50c4e366a814527da8642661e56a2a9615482bf92f6f","name":"Breeze Cache [breeze] < 2.2.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-23999","name":"CVE-2025-23999","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-23999","description":"[en] Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n\/a through <= 2.2.13.","date":"2025-06-18"},{"id":"a62b1769f3afd12dac8858bf2d2a6fbbba08e6ed","name":"WordPress Breeze Plugin <= 2.2.13 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/breeze\/vulnerability\/wordpress-breeze-plugin-2-2-13-broken-access-control-vulnerability","description":"<p>WordPress Breeze Plugin <= 2.2.13 is vulnerable to Broken Access Control<\/p><p>Software: Breeze<\/p><p>Fixed in version 2.2.14 <\/p><p>Affected Version <= 2.2.13<\/p><p>CVE: CVE-2025-23999<\/p>","date":"2025-06-18"},{"id":"6371480d10dc1e6ce3b86dc24c6dfe168d4a995b","name":"Breeze <= 2.2.13 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/breeze\/breeze-2213-missing-authorization","description":"The Breeze \u2013 WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.","date":"2025-06-18"},{"id":"EUVD-2025-18635","name":"EUVD-2025-18635","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-18635","description":"Missing Authorization vulnerability in Cloudways Breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n\/a through 2.2.13.","date":"2025-06-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f71eddb823065efcd7ad1dc71eff52c7243d3ee6b6555380a7ba263a34de2af2","name":"Breeze Cache [breeze] < 2.2.22","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.22","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-69364","name":"CVE-2025-69364","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-69364","description":"[en] Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n\/a through <= 2.2.21.","date":"2026-01-06"},{"id":"3aa8eef6aa1db04b6855b1d70d0e621c0e7b8cbb","name":"Breeze <= 2.2.21 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/breeze\/breeze-2221-missing-authorization-2","description":"The Breeze Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.21. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-01-13"},{"id":"EUVD-2026-0986","name":"EUVD-2026-0986","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-0986","description":"Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n\/a through <= 2.2.21.","date":"2026-01-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"n","a":"l","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:L","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"none","a":"low","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"804e6d8fd5997f344cb2d12875185d9d9f0f2d61920b6fe10a5cb221ce9ecc99","name":"Breeze Cache [breeze] < 2.2.22","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.22","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-13864","name":"CVE-2025-13864","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-13864","description":"[en] The Breeze - WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized cache clearing in all versions up to, and including, 2.2.21. This is due to the REST API endpoint `\/wp-json\/breeze\/v1\/clear-all-cache` being registered with `permission_callback => '__return_true'` and authentication being disabled by default when the API is enabled. This makes it possible for unauthenticated attackers to clear all site caches (page cache, Varnish, and Cloudflare) via a simple POST request, granted the administrator has enabled the API integration feature.","date":"2026-02-19"},{"id":"5c62caa598d291f80fdde4c02b2492a0a7c74aa6","name":"Breeze \u2013 WordPress Cache Plugin <= 2.2.21 - Missing Authorization to Cache Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/breeze\/breeze-wordpress-cache-plugin-2221-missing-authorization-to-cache-deletion","description":"The Breeze - WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized cache clearing in all versions up to, and including, 2.2.21. This is due to the REST API endpoint `\/wp-json\/breeze\/v1\/clear-all-cache` being registered with `permission_callback => '__return_true'` and authentication being disabled by default when the API is enabled. This makes it possible for unauthenticated attackers to clear all site caches (page cache, Varnish, and Cloudflare) via a simple POST request, granted the administrator has enabled the API integration feature.","date":"2026-02-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7d8bd49ae1628730052f07177c74b7a10c0b5feed2f2277b47f54b4f86b7de49","name":"Breeze Cache [breeze] < 2.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-3844","name":"CVE-2026-3844","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-3844","description":"[en] The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if \"Host Files Locally - Gravatars\" is enabled, which is disabled by default.","date":"2026-04-23"},{"id":"79c4a3b626d6131d436727fbe962094ac131426a","name":"Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/breeze\/breeze-cache-244-unauthenticated-arbitrary-file-upload-via-fetch-gravatar-from-remote","description":"The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if \"Host Files Locally - Gravatars\" is enabled, which is disabled by default.","date":"2026-04-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"84950a9c9342eac8ccc861a8d9087b90dbc2632d2e2c18cd1e6459eb7d40cce0","name":"Breeze Cache [breeze] < 2.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-2128","name":"CVE-2026-2128","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-2128","description":"[en] The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versions up to, and including, 2.5.2 This is due to improper verification of the `wordpress_logged_in_` cookie in the `inc\/cache\/execute-cache.php` file when the \"Cache Logged-in Users\" setting is enabled. The plugin parses the username directly from the cookie value (e.g., `username|hash`) using `substr()` to retrieve the corresponding cache file but fails to verify the session's cryptographic signature or validity with WordPress core. This makes it possible for unauthenticated attackers to supply a crafted cookie (e.g., `wordpress_logged_in_fake=admin|fake`) to trick the plugin into serving the cached HTML content generated for an administrator, leading to the disclosure of sensitive information such as private posts (including their full content), the Admin Bar, WordPress nonces, and other data visible only to logged-in administrators or other users.","date":"2026-05-29"},{"id":"dd70f664e9a0db28ee974bf4bddb2ba5ad445c64","name":"Breeze Cache <= 2.5.2 - Unauthenticated Exposure of Sensitive Information to an Unauthorized Actor via Crafted Login Cookie","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/breeze\/breeze-cache-252-unauthenticated-exposure-of-sensitive-information-to-an-unauthorized-actor-via-crafted-login-cookie","description":"The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versions up to, and including, 2.5.2 This is due to improper verification of the `wordpress_logged_in_` cookie in the `inc\/cache\/execute-cache.php` file when the \"Cache Logged-in Users\" setting is enabled. The plugin parses the username directly from the cookie value (e.g., `username|hash`) using `substr()` to retrieve the corresponding cache file but fails to verify the session's cryptographic signature or validity with WordPress core. This makes it possible for unauthenticated attackers to supply a crafted cookie (e.g., `wordpress_logged_in_fake=admin|fake`) to trick the plugin into serving the cached HTML content generated for an administrator, leading to the disclosure of sensitive information such as private posts (including their full content), the Admin Bar, WordPress nonces, and other data visible only to logged-in administrators or other users.","date":"2026-05-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"477d63ed2ae374977a8a5d70ea9ec12bb7c0e776caaf9cad56871779b014ef77","name":"Breeze Cache [breeze] < 2.5.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.5.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-10551","name":"CVE-2026-10551","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-10551","description":"[en] The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.","date":"2026-07-13"},{"id":"7f9860a62750bc5a2ef29d29692d80cd445e7a69","name":"Breeze Cache <= 2.5.5 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/941c9586-96a2-434e-af0d-c488e22ef97f","description":"The Breeze Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-06-22"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"106da92403af70d33702faa00f847ac905a48d090dc781ed509a0cd27a5b829d","name":"Breeze Cache [breeze] < 2.5.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.5.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-73356","name":"CVE-2026-73356","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-73356","description":"[en] Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.","date":"2026-08-18"},{"id":"fd970157bda9c3146ea36268db771e3a8114ec29","name":"Breeze Cache <= 2.5.12 - Missing Authorization to Unauthenticated Arbitrary Content Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/breeze\/breeze-cache-2512-missing-authorization-to-unauthenticated-arbitrary-content-deletion","description":"The Breeze Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.5.12. This makes it possible for unauthenticated attackers to delete arbitrary content.","date":"2026-06-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"h","score":"8.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:H","score":"8.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"18267748f6c582cd0674d9f4f952fae3fa3e0d00bad4ee825d112bfe98f5027b","name":"Breeze Cache [breeze] < 2.5.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.5.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-79706","name":"CVE-2026-79706","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-79706","description":"[en] The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to build the paths of the files it caches, allowing unauthenticated attackers to create files at arbitrary locations on the server, outside the intended cache directory.","date":"2026-08-28"},{"id":"681e67235a2484eaa85dce7399667ff0e2de36bb","name":"Breeze Cache < 2.5.13 - Unauthenticated File Creation via Path Traversal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/breeze\/breeze-cache-2513-unauthenticated-file-creation-via-path-traversal","description":"The Breeze Cache plugin for WordPress is vulnerable to Path Traversal in all versions up to 2.5.13. This is due to insufficient validation of a user supplied path. This makes it possible for unauthenticated attackers to create files outside of the intended directory.","date":"2026-08-14"}],"impact":{"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"24a8cf5dce28f3cd67291da20a59bcc6755eb8526819fd33cda874e2530e45ce","name":"Breeze Cache [breeze] >= 1.2.5 - < 2.5.15","description":null,"operator":{"min_version":"1.2.5","min_operator":"ge","max_version":"2.5.15","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-79713","name":"CVE-2026-79713","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-79713","description":"[en] The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have a page rendered under their own request context stored under, and served from, the clean URL's cache entry to every subsequent visitor.","date":"2026-09-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"l","a":"n","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-444","name":"Inconsistent Interpretation of HTTP Requests ('HTTP Request\/Response Smuggling')","description":"The product acts as an intermediary HTTP agent\n         (such as a proxy or firewall) in the data flow between two\n         entities such as a client and server, but it does not\n         interpret malformed HTTP requests or responses in ways that\n         are consistent with how the messages will be processed by\n         those entities that are at the ultimate destination."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1789801530"}