PT-2026-34629 · WordPress · Breeze Cache
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Breeze Cache versions prior to 2.4.5
Description
An arbitrary file upload flaw exists in the Breeze Cache plugin for WordPress, affecting approximately 400,000 active installations. The issue occurs within the
fetch gravatar from remote() function due to missing file type validation and an incorrect regular expression that allows URLs to be extracted from the alt attribute of image tags instead of just the src attribute. Unauthenticated attackers can exploit this by manipulating the display name of a comment to include a malicious URL pointing to a PHP file. When processed, the plugin downloads and saves the file to the server, potentially allowing remote code execution through the upload of PHP backdoors. This is only exploitable if the "Host Files Locally - Gravatars" setting is enabled. Real-world exploitation began immediately upon disclosure on April 22, 2026, with over 30,000 attempts blocked by security firewalls. Attackers have been observed uploading self-deleting PHP droppers to create backdoors and rogue administrator accounts.Recommendations
Update Breeze Cache to version 2.4.5 or later.
As a temporary mitigation, disable the "Host Files Locally - Gravatars" setting.
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Breeze Cache