← Back to CVE search

CVE-2026-79706

Breeze Cache

Description

The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to build the paths of the files it caches, allowing unauthenticated attackers to create files at arbitrary locations on the server, outside the intended cache directory.

CVSS 5.3EPSS 0.156%Risk 0.54
View source
Published
2026-08-28 08:16:42
Affected versions
<2.5.13
Type
Web application
Last modified
2026-08-28 16:18:27
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N