DEV Community

Cover image for Cloudways Patches Actively Exploited File Upload Flaw in Breeze Cache Plugin
BeyondMachines for BeyondMachines

Posted on • Originally published at beyondmachines.net

Cloudways Patches Actively Exploited File Upload Flaw in Breeze Cache Plugin

Summary

Cloudways patched a critical vulnerability in the Breeze Cache WordPress plugin (CVE-2026-3844) that allows unauthenticated attackers to upload malicious files and execute remote code. The flaw is currently under active exploitation, but it requires a non-default setting to be enabled in order to be exploited.

Take Action:

If you use the Breeze Cache WordPress plugin, update it to version 2.4.5 ASAP. If you can't update right away, disable the "Host Files Locally - Gravatars" setting as a temporary workaround until you can apply the update.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)