Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844)
ID: 1e9b6503-8208-51a2-8981-223ee2a09957
STIX ID: report--1e9b6503-8208-51a2-8981-223ee2a09957
Feed Name: Security Affairs
Threat Score
**CVE-2026-3844 (Breeze Cache)** — A critical arbitrary file upload flaw (CVSS 9.8) in the Breeze Cache WordPress plugin (<=2.4.4) allows unauthenticated attackers to upload files and potentially achieve remote code execution when the "Host Files Locally – Gravatars" option is enabled; the issue is fixed in 2.4.5 and active exploitation has been observed, with thousands of attack blocks reported by Wordfence. Update to 2.4.5 or disable the plugin immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
