PT-2026-34629 · WordPress · Breeze Cache

·

CVE-2026-3844

·

Published

2026-04-23

·

Updated

2026-07-13

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Breeze Cache versions prior to 2.4.5
Description An arbitrary file upload flaw exists in the Breeze Cache plugin for WordPress, affecting approximately 400,000 active installations. The issue occurs within the fetch gravatar from remote() function due to missing file type validation and an incorrect regular expression that allows URLs to be extracted from the alt attribute of image tags instead of just the src attribute. Unauthenticated attackers can exploit this by manipulating the display name of a comment to include a malicious URL pointing to a PHP file. When processed, the plugin downloads and saves the file to the server, potentially allowing remote code execution through the upload of PHP backdoors. This is only exploitable if the "Host Files Locally - Gravatars" setting is enabled. Real-world exploitation began immediately upon disclosure on April 22, 2026, with over 30,000 attempts blocked by security firewalls. Attackers have been observed uploading self-deleting PHP droppers to create backdoors and rogue administrator accounts.
Recommendations Update Breeze Cache to version 2.4.5 or later. As a temporary mitigation, disable the "Host Files Locally - Gravatars" setting.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3844

Affected Products

Breeze Cache