WordPress Plugin Vulnerabilities

Breeze Cache < 2.5.13 - Unauthenticated File Creation via Cache Path Traversal

Description

The plugin does not sanitise a value taken from the request before using it to build the paths of the files it caches, allowing unauthenticated attackers to create files at arbitrary locations on the server, outside the intended cache directory.

The resulting file extension is constrained and the content is not attacker-controlled, so the impact is limited to file creation and disk consumption; where an optional asset optimisation feature is enabled, existing site asset files can also be overwritten. On Windows hosts the same flaw additionally allows the planted file to be served publicly, and an existing file of the same type at the chosen location to be deleted.

Proof of Concept

Affects Plugins

Fixed in 2.5.13

References

Miscellaneous

Original Researcher
Jakub Herman
Submitter
Jakub Herman
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-08-26 (about 2 days ago)
Added
2026-08-26 (about 1 day ago)
Last Updated
2026-08-26 (about 1 day ago)

Other