WordPress sites face attacks exploiting Breeze Cache plugin vulnerability

heise.de (German)

WordPress sites using the Breeze Cache plugin are being targeted by attackers exploiting a critical vulnerability to install backdoors. Researchers observed over 30,000 attack attempts since April, with a specific function needing to be active for exploitation. A patched version, 2.4.5, is available. The vulnerability, CVE-2026-3844, allows unauthenticated attackers to upload malicious code due to insufficient file validation.


With a significance score of 1.3, this news ranks in the top 47% of today's 33623 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers:


WordPress sites face attacks exploiting Breeze Cache plugin vulnerability | News Minimalist