CVE-2026-79706
Deferred Deferred - Pending Action

Arbitrary File Write in Breeze Cache WordPress Plugin

Vulnerability report for CVE-2026-79706, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: WPScan

Description

The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to build the paths of the files it caches, allowing unauthenticated attackers to create files at arbitrary locations on the server, outside the intended cache directory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-09-18
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wordpress breeze_cache to 2.5.13 (exc)
wpbeaverbuilder breeze_cache to 2.5.13 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Breeze Cache WordPress plugin before version 2.5.13 has a vulnerability where it does not sanitize a value from the request before using it to build file paths for cached content. This allows unauthenticated attackers to create files at arbitrary locations on the server outside the intended cache directory.

Detection Guidance

Check if the Breeze Cache WordPress plugin version is below 2.5.13. Look for unexpected files in cache directories or arbitrary server locations. Monitor for unusual file creation or disk usage spikes.

Impact Analysis

This vulnerability allows attackers to create files anywhere on the server, consume disk space, and potentially overwrite existing site asset files if the asset optimization feature is enabled. On Windows hosts, attackers can serve created files publicly and delete existing files of the same type at chosen locations.

Compliance Impact

This vulnerability could lead to unauthorized file creation or modification on the server, potentially exposing sensitive data. For GDPR, this may result in unauthorized access to personal data. For HIPAA, it could compromise protected health information if files are created or overwritten inappropriately.

Mitigation Strategies

Update the Breeze Cache plugin to version 2.5.13 or later immediately. Disable the asset optimization feature if enabled. Review server files for unauthorized changes and restrict write permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79706. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart