logo

Over 400,000 WordPress Sites at Risk as “Breeze” Plugin Zero-Day Is Exploited in the Wild

ID: 67a1fdc5-afcb-501c-8c92-56cbdbc39436

STIX ID: report--67a1fdc5-afcb-501c-8c92-56cbdbc39436

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical arbitrary file upload vulnerability (CVE-2026-3844, CVSS 9.8) in the Breeze WordPress caching plugin can allow unauthenticated attackers to upload and execute malicious files (e.g., PHP web shells) if the "Host Files Locally – Gravatars" option is enabled; researchers observed 172 blocked exploitation attempts in 24 hours. Site owners should immediately update to Breeze 2.4.5, disable the Gravatars local-hosting option if they cannot update, and scan /wp-content/uploads/ for unexpected PHP files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.