WordPress Plugin Vulnerabilities
Breeze Cache < 2.5.13 - Unauthenticated File Creation via Cache Path Traversal
Description
The plugin does not sanitise a value taken from the request before using it to build the paths of the files it caches, allowing unauthenticated attackers to create files at arbitrary locations on the server, outside the intended cache directory.
The resulting file extension is constrained and the content is not attacker-controlled, so the impact is limited to file creation and disk consumption; where an optional asset optimisation feature is enabled, existing site asset files can also be overwritten. On Windows hosts the same flaw additionally allows the planted file to be served publicly, and an existing file of the same type at the chosen location to be deleted.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Jakub Herman
Submitter
Jakub Herman
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-26 (about 2 days ago)
Added
2026-08-26 (about 1 day ago)
Last Updated
2026-08-26 (about 1 day ago)