CVE-2026-3844Active Exploitation

CRITICALCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 11 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if "Host Files Locally - Gravatars" is enabled, which is disabled by default.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 30 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 55 mentions across 23 observed days

What's happening

  • Active exploitation reported across 30 signals
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 10 signals
  • Patch or workaround mentioned in 18 signals
  • Technical details provided in 41 signals
  • Disclosure: 7 classified signals
  • Peaked 20d ago at 11 mentions (2026-04-25); latest day: 2
  • 55 total mentions across 23 days

Deep dive

Activity timeline55 mentions / 23d
036811Mentions · 2026-04-23: 7Mentions · 2026-04-24: 7Mentions · 2026-04-25: 11Mentions · 2026-04-26: 2Mentions · 2026-04-27: 3Mentions · 2026-04-30: 3Mentions · 2026-05-01: 1Mentions · 2026-05-05: 4Mentions · 2026-05-06: 1Mentions · 2026-05-07: 2Mentions · 2026-05-11: 1Mentions · 2026-05-13: 1Mentions · 2026-05-21: 1Mentions · 2026-05-22: 1Mentions · 2026-05-23: 1Mentions · 2026-05-26: 1Mentions · 2026-06-23: 1Mentions · 2026-06-24: 1Mentions · 2026-07-12: 1Mentions · 2026-07-29: 1Mentions · 2026-08-03: 1Mentions · 2026-09-09: 1Mentions · 2026-10-08: 2PoC Mentioned / Linked · 2026-04-23: 1PoC Mentioned / Linked · 2026-04-24: 1PoC Mentioned / Linked · 2026-04-25: 1PoC Mentioned / Linked · 2026-04-26: 1PoC Mentioned / Linked · 2026-04-27: 1PoC Mentioned / Linked · 2026-04-30: 1PoC Mentioned / Linked · 2026-05-23: 1PoC Mentioned / Linked · 2026-07-29: 1PoC Mentioned / Linked · 2026-08-03: 1PoC Mentioned / Linked · 2026-09-09: 1Exploit Tool / Code · 2026-04-25: 1Exploit Tool / Code · 2026-04-27: 1Exploit Tool / Code · 2026-05-05: 1Exploit Tool / Code · 2026-05-23: 1Exploit Tool / Code · 2026-07-29: 1Active Exploitation · 2026-04-23: 4Active Exploitation · 2026-04-24: 4Active Exploitation · 2026-04-25: 10Active Exploitation · 2026-04-26: 1Active Exploitation · 2026-04-27: 1Active Exploitation · 2026-05-05: 2Active Exploitation · 2026-05-06: 1Active Exploitation · 2026-05-07: 2Active Exploitation · 2026-05-22: 1Active Exploitation · 2026-05-23: 1Active Exploitation · 2026-05-26: 1Active Exploitation · 2026-07-12: 1Active Exploitation · 2026-07-29: 1Patch / Workaround · 2026-04-23: 2Patch / Workaround · 2026-04-24: 2Patch / Workaround · 2026-04-25: 3Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-05-07: 2Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-07-29: 1Technical Details · 2026-04-23: 7Technical Details · 2026-04-24: 6Technical Details · 2026-04-25: 6Technical Details · 2026-04-26: 2Technical Details · 2026-04-27: 2Technical Details · 2026-04-30: 3Technical Details · 2026-05-01: 1Technical Details · 2026-05-05: 4Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 2Technical Details · 2026-05-11: 1Technical Details · 2026-05-21: 1Technical Details · 2026-05-22: 1Technical Details · 2026-05-23: 1Technical Details · 2026-06-24: 1Technical Details · 2026-07-29: 1Technical Details · 2026-09-09: 104-2304-2504-2705-0105-0605-1105-2105-2306-2307-1208-0310-08
Signal classification6 categories
Active Exploitation
3056.6%
Disclosure
713.2%
Patch
611.3%
General
59.4%
PoC
47.5%
Exploit
11.9%
Referenced assets37 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-237
Active Exploitation4Disclosure1Patch2
2026-04-247
Active Exploitation4Disclosure1Patch1PoC1
2026-04-2511
Active Exploitation10PoC1
2026-04-262
Active Exploitation1PoC1
2026-04-273
Active Exploitation1Disclosure1Exploit1
2026-04-303
Disclosure1General1Patch1
2026-05-011
Disclosure1
2026-05-054
Active Exploitation2General2
2026-05-061
Active Exploitation1
2026-05-072
Active Exploitation2
2026-05-111
Patch1
2026-05-131
Patch1
2026-05-211
Disclosure1
2026-05-221
Active Exploitation1
2026-05-231
Active Exploitation1
2026-05-261
Active Exploitation1
2026-06-231
General1
2026-06-241
General1
2026-07-121
Active Exploitation1
2026-07-291
Active Exploitation1
2026-08-031
Disclosure1
2026-09-091
PoC1
Full discourse20 posts
  • elhacker.NET@elhackernet
    Disclosure

    Más de 400.000 sitios WordPress en riesgo por fallo en plugin Breeze Cache (CVE-2026-3844) https://blog.elhacker.net/2026/04/mas-de-400000-sitios-wordpress-en.html

    Post summary

    The article announces that more than 400,000 WordPress sites are at risk from CVE-2026‑3844 in the Breeze Cache plugin, but provides no further technical or mitigation details.

    0701131.6K
    140.9K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Active Exploitation

    Saldırganların WordPress, Joomla gibi sistemlere saldırırken kullandığı CVE'ler : – CVE-2026-3844 (WordPress Breeze) – CVE-2026-48907 (Joomla JCE) Diğerleri: CVE-2026-1969, CVE-2026-3300, CVE-2026-0740, CVE-2026-6433, CVE-2025-7443, CVE-2025-7852, CVE-2025-12057, CVE-2020-36847 ve CVE-2020-25213

    Post summary

    The post lists CVEs actively exploited by attackers on WordPress and Joomla platforms, but contains no additional technical details, exploit code, or mitigation information.

    1301142.4K
    2.2K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844) https://securityaffairs.com/191267/uncategorized/over-400000-sites-at-risk-as-hackers-exploit-breeze-cache-plugin-flaw-cve-2026-3844.html

    Post summary

    The article reports that over 400,000 sites are at risk as attackers are actively exploiting the Breeze Cache plugin flaw, CVE-2026-3844, with no mention of a patch or PoC.

    0411021.7K
    158.1K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Active Exploitation

    🚨 WordPress plugin under active attack Breeze Cache flaw (CVE-2026-3844) → unauth file upload → full site takeover ⚠️ Affected: 400K+ sites ✅ Fix: • Update to v2.4.5 • Disable “Host Files Locally” if not patched https://www.bleepingcomputer.com/news/security/hackers-exploit-file-upload-bug-in-breeze-cache-wordpress-plugin/

    Post summary

    Breeze Cache plugin faces active exploitation via an unauthenticated file upload flaw that lets attackers fully take over sites; over 400k sites are affected and can be mitigated by updating to v2.4.5 or disabling local file hosting.

    11096894
    16.1K followersView on X
  • Netlas.io@Netlas_io
    Active Exploitation

    CVE-2026-3844: Unrestricted Arbitrary File Upload in Breeze WordPress plugin, 9.8 rating 🔥 Unrestricted Arbitrary File Upload in Breeze WordPress plugin allows an unauthenticated attacker to upload web shell and execute it remotely. This vulnerability is already being actively exploited in the wild! 👉 https://nt.ls/61VeQ

    Post summary

    The post announces CVE-2026-3844, detailing an unrestricted arbitrary file upload flaw in the Breeze WordPress plugin, and claims the vulnerability is currently being exploited in the wild.

    13075771
    7.6K followersView on X
  • Teegra 🧝‍♀️𝕏@Teeegra
    Active Exploitation

    هکرها در حال بهره‌برداری فعال از یک آسیب‌پذیری بحرانی در افزونه Breeze Cache وردپرس (Wordpress) هستند که به مهاجمان اجازه می‌دهد بدون احراز هویت (unauthenticated)، فایل‌های دلخواه را روی سرور بارگذاری کنند. این آسیب‌پذیری با شناسه CVE-2026-3844 ردیابی می‌شود، امتیاز بحرانی ۹.۸ از ۱۰ دریافت کرده و تاکنون بیش از ۱۷۰ تلاش بهره‌برداری توسط راهکار امنیتی Wordfence شناسایی شده است. این افزونه که متعلق به Cloudways است، بیش از ۴۰۰ هزار نصب فعال دارد!

    Post summary

    The post reports that attackers are actively exploiting CVE-2026-3844 in the Breeze Cache plugin, enabling unauthenticated arbitrary file uploads, with over 170 attempts detected by Wordfence—yet no patch or exploit code is disclosed.

    000113810
    19.0K followersView on X
  • Ctrl-Alt-Intel@ctrlaltintel
    General

    Most successful CVEs observed were: CVE-2026-3844 - WP Breeze Cache CVE-2026-1969 - WP ThemeRex (2/n) https://t.co/VvjKXP70se

    Post summary

    The tweet simply lists two CVE identifiers for WP Breeze Cache and WP ThemeRex without providing any additional technical details, evidence of exploitation, or remediation information.

    12091564
    1.3K followersView on X
  • Wordfence@wordfence
    Active Exploitation

    Attackers Actively Exploiting Critical Vulnerability in Breeze Cache Plugin Attackers are actively exploiting a critical arbitrary file upload vulnerability (CVE-2026-3844, CVSS 9.8) in Breeze Cache, allowing unauthenticated attackers to upload PHP backdoors and achieve remote code execution. The Wordfence Firewall has blocked over 30,000 exploit attempts since disclosure. https://www.wordfence.com/blog/2026/05/attackers-actively-exploiting-critical-vulnerability-in-breeze-cache-plugin/

    Post summary

    Attackers are actively exploiting CVE-2026-3844 in Breeze Cache, using an arbitrary file upload flaw to upload PHP backdoors and achieve remote code execution.

    05051392
    8.2K followersView on X
  • yousukezan@yousukezan
    Active Exploitation

    WordPressプラグインBreeze Cacheに深刻な脆弱性が見つかり、既に大規模な攻撃が発生している。認証不要でファイルをアップロード可能となり、最悪の場合サイト乗っ取りに至る危険性がある。 問題はCVE-2026-3844として追跡され、CVSSは9.8と極めて高い。対象はBreeze Cacheの2.4.4以前で、ファイルタイプ検証の欠如により任意ファイルのアップロードが可能となる。これによりリモートコード実行やサイト完全侵害につながる恐れがある。 このプラグインはCloudwaysが開発し、40万以上のサイトで利用されている。脆弱性は研究者のHung Nguyenが発見した。 攻撃はすでに活発化しており、Wordfenceは24時間で約4000件の攻撃をブロックしたと報告している。なお悪用には「Host Files Locally – Gravatars」機能が有効である必要がある。 修正はバージョン2.4.5で提供されており、利用者は速やかな更新または機能無効化が求められる。 https://securityaffairs.com/191267/uncategorized/over-400000-sites-at-risk-as-hackers-exploit-breeze-cache-plugin-flaw-cve-2026-3844.html

    Post summary

    CVE-2026-3844 in Breeze Cache allows unauthenticated file upload that can lead to remote code execution; attacks are already active, and the vendor has released a patch in version 2.4.5. Users should update promptly or disable the vulnerable feature.

    001642.0K
    14.4K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    CVE-2026-3844 Breeze Cache plugin for WordPress, PoC and lab for validation using raptor, https://github.com/dinosn/CVE-2026-3844

    Post summary

    A PoC for CVE-2026-3844 targeting the WordPress Breeze Cache plugin has been posted and lab‑validated using Raptor, with code hosted on GitHub.

    010411.3K
    158.1K followersView on X
  • John@p3Nt3st3r_sTAr
    Active Exploitation

    CVE-2026-3844 https://www.wordfence.com/blog/2026/05/attackers-actively-exploiting-critical-vulnerability-in-breeze-cache-plugin/ https://t.co/7DSJM8ar3d

    Post summary

    The CVE‑2026‑3844 vulnerability is being actively exploited by attackers, as reported by Wordfence, but no PoC, exploit code, patch, or detailed technical information is provided.

    01022318
    45 followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Active Exploitation

    🚨 400K+ WordPress sites at risk via Breeze Cache RCE (CVE-2026-3844) → Attack: Unauthenticated file upload via missing validation → possible RCE → Impact: Full website takeover 💡 Insight: One misconfigured feature = full compromise (not enabled by default, but widely overlooked) ⚠️ Action: Update to v2.4.5 immediately Disable “Host Files Locally – Gravatars” Monitor for suspicious file uploads https://securityaffairs.com/191267/uncategorized/over-400000-sites-at-risk-as-hackers-exploit-breeze-cache-plugin-flaw-cve-2026-3844.html

    Post summary

    Over 400,000 WordPress sites are currently being exploited by an unauthenticated file‑upload flaw in Breeze Cache (CVE‑2026‑3844). Site owners should upgrade to v2.4.5, disable the Host Files Locally feature, and monitor for suspicious uploads.

    01012399
    7.6K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Critical WordPress plugin flaw under active exploitation since disclosure. CVE-2026-3844 (CVSS 9.8) in Breeze Cache allows unauthenticated arbitrary file upload via gravatar processing, leading to RCE on 400k+ sites. Key technical details: • Vulnerability in fetch_gravatar_from_remote() function - regex extracts URLs from alt attributes, bypassing file validation • Exploit: Attackers post comments with malicious URLs in author name field, plugin downloads/saves PHP webshells to /wp-content/cache/breeze-extra/gravatars/ • Only exploitable when "Host Files Locally - Gravatars" setting enabled (disabled by default) • 30,000+ blocked attempts since April 22nd disclosure, mass exploitation April 24-29 Attack artifacts: • Malicious PHP files in gravatar cache directory • Rogue admin accounts with @wordpress.org emails (randomhex@wordpress.org pattern) • Self-deleting droppers creating backdoors named wp-<function>-<6chars>.php • Top attacking IPs: 15[.]235[.]188[.]154, 188[.]166[.]212[.]28, 124[.]248[.]183[.]139 Hunt for unknown PHP files in /wp-content/cache/breeze-extra/gravatars/ and suspicious admin accounts. Update to Breeze Cache v2.4.5+ immediately. #DFIR_Radar

    Post summary

    CVE-2026-3844 is actively exploited on over 400k WordPress sites via an arbitrary file upload that leads to RCE; users are urged to update immediately to Breeze Cache v2.4.5+ to mitigate the vulnerability.

    11010190
    1.4K followersView on X
  • ♫NØX♥H♪@_Why_Noot

    NØX Echo Lineage Signal: CVE-2026-3844 Entity: Breeze Cache Lineage: Public vulnerability → Public exploit/PoC → Observed exploitation Relationship: - Breeze Cache → CVE-2026-3844 → Evidence → Operational Risk Current State:

    2000045
    8 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    The impact is visceral: Cloudways Breeze Cache plugin (CVE-2026-3844): 3,900+ exploits hit 400K WordPress sites in 24 hours of disclosure. Patches still rolling out. Protobuf.js RCE: 52 million weekly downloads exposed to injection attacks. Proof-of-concept published.…

    Post summary

    The text highlights that CVE‑2026‑3844 has been actively exploited, affecting over 400,000 WordPress sites within a day of disclosure, while Protobuf.js faces widespread RCE risk; patches are still being issued.

    1000192
    227 followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    Weekly WordPress security report: 157 vulnerabilities across 122 plugins and 27 themes, including 6 critical-rated flaws. CVE-2026-3844 (Breeze Cache) and CVE-2026-6235 (Sendmachine) enable unauthenticated RCE. #DFIR_Radar https://t.co/szjCzDq5w4

    Post summary

    The tweet announces that CVE‑2026‑3844 and CVE‑2026‑6235 are unauthenticated RCE vulnerabilities in WordPress plugins, but offers no patches, PoC, or evidence of current exploitation.

    10010107
    1.7K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-3844 - critical 🚨 Breeze &lt;= 2.4.4 - Arbitrary File Upload &gt; Breeze Cache WordPress plugin &lt;= 2.4.4 contains an unrestricted file upload vulnerabi... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-3844 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces the discovery of CVE-2026-3844, a critical arbitrary file upload flaw in Breeze Cache WordPress plugin versions <=2.4.4, and directs readers to a link for additional details.

    00011132
    942 followersView on X
  • dbugs@ptdbugs
    Exploit

    Plugin for WordPress Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload to RCE via fetch_gravatar_from_remote CVE: CVE-2026-3844 PT ID: PT-2026-34629 Vendor: cloudways Product: Breeze Cache (plugin for WordPress) CVSS: 9.8 Credits: Hung Nguyen Description: The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if "Host Files Locally - Gravatars" is enabled, which is disabled by default. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-3844 • https://www.wordfence.com/threat-intel/vulnerabilities/id/e342b1c0-6e7f-4e2c-8a52-018df12c12a0?source=cve • https://plugins.trac.wordpress.org/browser/breeze/tags/2.4.1/inc/class-breeze-cache-cronjobs.php#L119 • https://plugins.trac.wordpress.org/browser/breeze/tags/2.4.1/inc/class-breeze-cache-cronjobs.php#L89 • https://plugins.trac.wordpress.org/changeset/3511463/breeze Exploit: https://github.com/dinosn/CVE-2026-3844 #dbugs_vuln

    Post summary

    The Breeze Cache plugin for WordPress allows unauthenticated arbitrary file uploads that can lead to remote code execution, with a publicly available exploit script on GitHub confirming its feasibility.

    00011121
    799 followersView on X
  • CiberBaur@BotBauR
    Active Exploitation

    ⚠️ ALERTA: Una vulnerabilidad crítica en el plugin Breeze Cache de WordPress (CVE-2026-3844) está siendo explotada. Actualiza YA para evitar subidas de archivos sin autenticación. https://securityaffairs.com/191267/uncategorized/over-400000-sites-at-risk-as-hackers-exploit-breeze-cache-plugin-flaw-cve-2026-3844.html #CiberseguridadMX #VulnerabilidadCrítica #WordPress

    Post summary

    A critical vulnerability (CVE‑2026‑3844) in the Breeze Cache plugin is actively exploited, enabling unauthenticated file uploads; all WordPress sites should update immediately to mitigate the risk.

    0002068
    151 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Critical RCE vulnerability (CVE-2026-3844) found in Breeze Cache WordPress plugin allows unauthenticated file uploads via fetch_gravatar_from_remote when Gravatars add-on is enabled. Patch 2.4.5 released. #WordPressPlugin #RemoteCodeExec #India https://ift.tt/Pnwthol

    Post summary

    A critical remote code execution flaw in Breeze Cache WordPress plugin has been identified, allowing unauthenticated file uploads, and a vendor patch (2.4.5) has been released to remediate it.

    00020223
    4.4K followersView on X

Explore more