Over 400,000 WordPress Sites at Risk as “Breeze” Plugin Zero-Day Is Exploited in the Wild
ID: 67a1fdc5-afcb-501c-8c92-56cbdbc39436
STIX ID: report--67a1fdc5-afcb-501c-8c92-56cbdbc39436
Feed Name: securityonline.info
A critical arbitrary file upload vulnerability (CVE-2026-3844, CVSS 9.8) in the Breeze WordPress caching plugin can allow unauthenticated attackers to upload and execute malicious files (e.g., PHP web shells) if the "Host Files Locally – Gravatars" option is enabled; researchers observed 172 blocked exploitation attempts in 24 hours. Site owners should immediately update to Breeze 2.4.5, disable the Gravatars local-hosting option if they cannot update, and scan /wp-content/uploads/ for unexpected PHP files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
