DEV Community

Cover image for Cloudways Patches Actively Exploited File Upload Flaw in Breeze Cache Plugin
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Cloudways Patches Actively Exploited File Upload Flaw in Breeze Cache Plugin

Summary

Cloudways patched a critical vulnerability in the Breeze Cache WordPress plugin (CVE-2026-3844) that allows unauthenticated attackers to upload malicious files and execute remote code. The flaw is currently under active exploitation, but it requires a non-default setting to be enabled in order to be exploited.

Take Action:

If you use the Breeze Cache WordPress plugin, update it to version 2.4.5 ASAP. If you can't update right away, disable the "Host Files Locally - Gravatars" setting as a temporary workaround until you can apply the update.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)