logo

Hackers exploit file upload bug in Breeze Cache WordPress plugin

ID: 31d3d0ac-421e-5153-b6f0-ddd484f1fcb5

STIX ID: report--31d3d0ac-421e-5153-b6f0-ddd484f1fcb5

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Bill Toulas

...
...

The Breeze Cache WordPress plugin has a critical file-upload vulnerability (CVE-2026-3844, CVSS 9.8) affecting versions up to 2.4.4 that can lead to remote code execution if the "Host Files Locally - Gravatars" option is enabled; Wordfence has observed active exploitation attempts and Cloudways released version 2.4.5 to fix the issue, with site owners advised to upgrade or disable the affected add-on.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.