logo

Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844)

ID: 1e9b6503-8208-51a2-8981-223ee2a09957

STIX ID: report--1e9b6503-8208-51a2-8981-223ee2a09957

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-04-25

Date Updated: 2026-04-25

Author: Pierluigi Paganini

...
...

**CVE-2026-3844 (Breeze Cache)** — A critical arbitrary file upload flaw (CVSS 9.8) in the Breeze Cache WordPress plugin (<=2.4.4) allows unauthenticated attackers to upload files and potentially achieve remote code execution when the "Host Files Locally – Gravatars" option is enabled; the issue is fixed in 2.4.5 and active exploitation has been observed, with thousands of attack blocks reported by Wordfence. Update to 2.4.5 or disable the plugin immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.