Hackers exploit file upload bug in Breeze Cache WordPress plugin
ID: 31d3d0ac-421e-5153-b6f0-ddd484f1fcb5
STIX ID: report--31d3d0ac-421e-5153-b6f0-ddd484f1fcb5
Feed Name: Bleeping Computer
Threat Score
The Breeze Cache WordPress plugin has a critical file-upload vulnerability (CVE-2026-3844, CVSS 9.8) affecting versions up to 2.4.4 that can lead to remote code execution if the "Host Files Locally - Gravatars" option is enabled; Wordfence has observed active exploitation attempts and Cloudways released version 2.4.5 to fix the issue, with site owners advised to upgrade or disable the affected add-on.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
