HomeSecurityWordPress: Hackers exploit vulnerability in Breeze Cache plugin

WordPress: Hackers exploit vulnerability in Breeze Cache plugin

A serious security threat has raised alarm in the WordPress community, as hackers are actively exploiting a critical flaw in the popular Breeze Cache plugin. The vulnerability allows attackers to upload arbitrary files to servers without any authentication process, paving the way for complete website compromise.

Breeze Cache WordPress plugin

The issue, listed as CVE-2026-3844, has already been used in over 170 recorded attacks according to data from Wordfence. This development confirms that this is not a theoretical scenario, but an active and evolving threat affecting real websites.

What is Breeze Cache and why is it so widespread?

Breeze Cache, developed by Cloudways, is one of the most widely used performance optimization plugins for WordPress. With over 400,000 active installations, it helps admins speed up page loading through caching, file optimization, and database cleanup.

See also: Security gaps in Phidias' Agorà – Data of 40,000 users exposed

Its popularity makes it a particularly attractive target for attackers. When such a widespread tool has a security flaw, the impact can spread across a large part of the internet, affecting businesses, online stores , and personal sites.

How the attack works and what is the risk?

The vulnerability was discovered by security researcher Hung Nguyen and rated 9.8/10, classifying it as a critical threat. According to Defiant, the issue arises from an incomplete file type check in a specific plugin function.

This vulnerability allows an unauthorized user to upload malicious files to the server. In advanced scenarios, the attack could lead to Remote Code Execution, giving the attacker complete control of the website. In other words, a hacker could install malware, steal data, or use the site for further attacks.

It is worth noting that the exploit is only possible when the “Host Files Locally – Gravatars” option is enabled, which is not active by default. However, many administrators enable it for performance reasons, unwittingly increasing the risk.

See also: Terrarium Sandbox: Critical vulnerability allows root code execution

WordPress: Hackers exploit vulnerability in Breeze Cache plugin

Cloudways' response and the importance of updates

Cloudways has already addressed the issue with Breeze Cache version 2.4.5, which was released earlier this week. The vulnerability affects all previous versions up to 2.4.4, making it critical to upgrade immediately.

Despite the fact that the new version has already had tens of thousands of downloads, it remains unknown how many websites are still exposed. The lack of data on how many users have enabled this feature makes it difficult to estimate the true scope of the threat.

What administrators should do immediately

Experts warn that delaying updates is one of the main reasons for successful cyberattacks. In the case of Breeze Cache, the recommendation is clear: immediately upgrade to the latest version or, alternatively, temporarily disable the plugin.

For those who cannot immediately proceed with the update, disabling the “Host Files Locally – Gravatars” option is a critical interim protection measure. In addition, it is recommended to use security tools and regularly monitor logs for suspicious activity.

See also: Claude Mythos discovered 271 vulnerabilities in Firefox

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

WordPress: Hackers exploit vulnerability in Breeze Cache plugin

The bigger picture of security in the WordPress ecosystem

This incident highlights a perennial issue in the WordPress ecosystem: the reliance on third-party plugins. While they offer flexibility and powerful features, they are also one of the most common entry points for attacks.

As cyberthreats become more targeted and automated, the need for timely updates, proper configuration management, and basic cybersecurity practices is more imperative than ever. CVE-2026-3844 serves as yet another reminder that even the most trusted tools can become a weak link if not used with care.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS