Breeze Cache <= 2.5.12 - Missing Authorization to Unauthenticated Arbitrary Content Deletion
medium
The Breeze Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.5.12. This makes it possible for unauthenticated attackers to delete arbitrary content.
- CVSS:
- 5.3
- Affected:
- up to 2.5.12
- Fixed in:
- 2.5.13
- Disclosed:
- Aug 14, 2026
CVE-2026-73356 on NVD →
Breeze Cache <= 2.5.5 - Unauthenticated Stored Cross-Site Scripting
high
The Breeze Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...
- CVSS:
- 7.2
- Affected:
- up to 2.5.5
- Fixed in:
- 2.5.6
- Disclosed:
- Jun 22, 2026
CVE-2026-10551 on NVD →
Breeze Cache <= 2.5.2 - Unauthenticated Exposure of Sensitive Information to an Unauthorized Actor via Crafted Login Cookie
medium
The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versions up to, and including, 2.5.2 This is due to improper verification of the `wordpress_logged_in_` cookie in the `inc/cache/execute-cache.php` file when the "Cache Logged-in Users" setting is enabled....
- CVSS:
- 5.3
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.3
- Disclosed:
- May 28, 2026
CVE-2026-2128 on NVD →
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
critical
The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which m...
- CVSS:
- 9.8
- Affected:
- up to 2.4.4
- Fixed in:
- 2.4.5
- Disclosed:
- Apr 22, 2026
CVE-2026-3844 on NVD →
Breeze Cache [breeze] < 2.2.22
unknown
[en] The Breeze - WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized cache clearing in all versions up to, and including, 2.2.21. This is due to the REST API endpoint `/wp-json/breeze/v1/clear-all-cache` being registered with `permission_callback => '__return_true'` and authentication being disab...
- Affected:
- up to 2.2.22
- Fixed in:
- 2.2.22
- Disclosed:
- Feb 19, 2026
CVE-2025-13864 on NVD →
Breeze – WordPress Cache Plugin <= 2.2.21 - Missing Authorization to Cache Deletion
medium
The Breeze - WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized cache clearing in all versions up to, and including, 2.2.21. This is due to the REST API endpoint `/wp-json/breeze/v1/clear-all-cache` being registered with `permission_callback => '__return_true'` and authentication being disabled b...
- CVSS:
- 5.3
- Affected:
- up to 2.2.21
- Fixed in:
- 2.2.22
- Disclosed:
- Feb 18, 2026
CVE-2025-13864 on NVD →
Breeze <= 2.2.21 - Missing Authorization
medium
The Breeze Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.21. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.2.21
- Fixed in:
- 2.2.22
- Disclosed:
- Jan 13, 2026
CVE-2025-69364 on NVD →
Breeze Cache [breeze] <= 2.2.21 (unfixed)
unknown
[en] Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n/a through <= 2.2.21.
- Affected:
- up to 2.2.21
- Fix:
- No patched version reported
- Disclosed:
- Jan 6, 2026
CVE-2025-69364 on NVD →
Breeze <= 2.2.13 - Missing Authorization
medium
The Breeze – WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.2.13
- Fixed in:
- 2.2.14
- Disclosed:
- Jun 18, 2025
CVE-2025-23999 on NVD →
Breeze Cache [breeze] < 2.2.14
unknown
[en] Missing Authorization vulnerability in Cloudways Breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n/a through 2.2.13.
- Affected:
- up to 2.2.14
- Fixed in:
- 2.2.14
- Disclosed:
- Jun 18, 2025
CVE-2025-23999 on NVD →
Breeze Cache [breeze] < 2.1.15
unknown
[en] Missing Authorization vulnerability in Cloudways Breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n/a through 2.1.14.
- Affected:
- up to 2.1.15
- Fixed in:
- 2.1.15
- Disclosed:
- Oct 29, 2024
CVE-2024-50422 on NVD →
Breeze Cache [breeze] < 2.1.15
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Cloudways Breeze allows Stored XSS.This issue affects Breeze: from n/a through 2.1.14.
- Affected:
- up to 2.1.15
- Fixed in:
- 2.1.15
- Disclosed:
- Oct 28, 2024
CVE-2024-50431 on NVD →
Breeze <= 2.1.14 - Missing Authorization
medium
The Breeze plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_to_default() function in versions up to, and including, 2.1.14. This makes it possible for unauthenticated attackers to reset to default settings.
- CVSS:
- 5.3
- Affected:
- up to 2.1.14
- Fixed in:
- 2.1.15
- Disclosed:
- Oct 24, 2024
CVE-2024-50422 on NVD →
Breeze <= 2.1.14 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Breeze plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that w...
- CVSS:
- 4.4
- Affected:
- up to 2.1.14
- Fixed in:
- 2.1.15
- Disclosed:
- Oct 24, 2024
CVE-2024-50431 on NVD →
Breeze Cache [breeze] < 2.1.4
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cloudways Breeze allows Stored XSS.This issue affects Breeze: from n/a through 2.1.3.
- Affected:
- up to 2.1.4
- Fixed in:
- 2.1.4
- Disclosed:
- Mar 27, 2024
CVE-2024-27188 on NVD →
Breeze <= 2.1.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via breeze_api_token
medium
The Breeze plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘breeze_api_token’ parameter in versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a...
- CVSS:
- 5.5
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.4
- Disclosed:
- Mar 25, 2024
CVE-2024-27188 on NVD →
Breeze <= 2.0.8 - Cross-Site Request Forgery via import_json_settings
medium
The Breeze plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.8. This is due to missing or incorrect nonce validation on the 'import_json_settings' function. This makes it possible for unauthenticated attackers to import plugin settings via a forged request granted th...
- CVSS:
- 4.3
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.9
- Disclosed:
- Sep 19, 2022
Breeze Cache [breeze] < 2.0.9
unknown
The Breeze plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.8. This is due to missing or incorrect nonce validation on the 'import_json_settings' function. This makes it possible for unauthenticated attackers to import plugin settings via a forged request granted th...
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.9
- Disclosed:
- Sep 19, 2022
Breeze – WordPress Cache Plugin <= 2.0.2 - Unprotected AJAX Actions
medium
Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability in Cloudways Breeze plugin <= 2.0.2 on WordPress allows users with a subscriber or higher user role to execute any of the wp_ajax_* actions in the class Breeze_Configuration which includes the ability to change any of the plugin's settings inclu...
- CVSS:
- 6.5
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.3
- Disclosed:
- May 2, 2022
CVE-2022-29444 on NVD →
Breeze Cache [breeze] < 2.0.3
unknown
[en] Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability in Cloudways Breeze plugin <= 2.0.2 on WordPress allows users with a subscriber or higher user role to execute any of the wp_ajax_* actions in the class Breeze_Configuration which includes the ability to change any of the plugin's settings...
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- May 2, 2022
CVE-2022-29444 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database