Skip to content

Known CVE

Breeze <= 2.4.4 - Arbitrary File Upload

Breeze Cache WordPress plugin <= 2.4.4 contains an unrestricted file upload vulnerability caused by missing file type validation in 'fetch_gravatar_from_remote' function, letting unauthenticated attackers upload arbitrary files, exploit requires 'Host Files Locally - Gravatars' enabled.

CVE-2026-3844

Critical2026CVSS 9.8CWE-434

cve2026 · wordpress · wp-plugin · wp · breeze · file-upload · rce · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website