CVE-2026-10551
Deferred Deferred - Pending Action

Breeze Cache Plugin Stored XSS via Minification

Vulnerability report for CVE-2026-10551, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-13

Last updated on: 2026-07-13

Assigner: WPScan

Description

The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-13
Last Modified
2026-07-13
Generated
2026-08-02
AI Q&A
2026-07-13
EPSS Evaluated
2026-08-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpbeaverbuilder breeze_cache to 2.5.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Breeze Cache WordPress plugin, before version 2.5.6, is vulnerable to an unauthenticated Stored Cross-Site Scripting (XSS) attack.

This vulnerability occurs because the plugin uses a predictable replacement hash during the HTML minification process and an exploitable regular expression.

An attacker can exploit this by anticipating the placeholder format and injecting arbitrary HTML attributes into the final HTML output.

Detection Guidance

There is no specific information provided about detection methods or commands to identify this vulnerability on your network or system.

Impact Analysis

This vulnerability allows an attacker to perform a Stored Cross-Site Scripting (XSS) attack without authentication.

Such an attack can lead to the injection of malicious HTML attributes into web pages served by the affected plugin, potentially compromising the security of users visiting the site.

The impact includes theft of user credentials, session hijacking, defacement, or distribution of malware through the affected website.

Compliance Impact

This vulnerability, being an unauthenticated Stored Cross-Site Scripting (XSS) issue, can have significant implications for compliance with standards and regulations like GDPR and HIPAA.

  • GDPR: The vulnerability allows attackers to inject arbitrary HTML attributes, which could lead to unauthorized access to user data or session hijacking. Under GDPR, organizations must protect personal data from unauthorized access or disclosure. A successful exploit could result in a data breach, leading to non-compliance with GDPR's data protection requirements (Articles 5, 25, and 32) and potential fines.
  • HIPAA: For organizations handling protected health information (PHI), this vulnerability could expose sensitive patient data if the compromised WordPress site is part of a healthcare-related system. HIPAA requires safeguards to ensure the confidentiality, integrity, and availability of PHI. A successful XSS attack could violate these safeguards, leading to non-compliance with the Security Rule (45 CFR Part 164, Subpart C).

Additionally, the CVSS score of 6.1 (or 8.8 as noted in Resource 1) indicates a moderate to high severity, which may trigger mandatory reporting requirements under regulations like GDPR if a breach occurs.

Mitigation Strategies

To mitigate this vulnerability, you should update the Breeze Cache WordPress plugin to version 2.5.6 or later, as versions prior to 2.5.6 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10551. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart