
PEACH
Un cadre d’isolation des locataires
CVE-2026-79706 is an unauthenticated file creation vulnerability via cache path traversal in the Breeze Cache WordPress plugin by Cloudways. The flaw allows unauthenticated attackers to create files at arbitrary locations on the server, outside the intended cache directory. It affects all versions of the Breeze Cache plugin before 2.5.13. The vulnerability was publicly disclosed on August 26, 2026, and assigned by WPScan. The CVSS category is estimated as HIGH, though a precise numeric score has not yet been published (WPScan, Feedly).
The root cause is insufficient input sanitization of a user-supplied value from the HTTP request that is used to construct file cache paths (CWE-434: Unrestricted Upload of File with Dangerous Type / path traversal). An unauthenticated attacker can manipulate this value to traverse outside the intended cache directory and write files to arbitrary server locations. The file extension is constrained and file content is not attacker-controlled, limiting direct code execution risk; however, when the optional asset optimization feature is enabled, existing site asset files can be overwritten. On Windows hosts, the vulnerability additionally allows the planted file to be served publicly and an existing file of the same type at the targeted location to be deleted. A proof-of-concept is scheduled for public release on September 26, 2026 (WPScan).
Successful exploitation allows unauthenticated attackers to create files at arbitrary locations on the server, which can lead to disk consumption and potential disruption of site functionality. When the optional asset optimization feature is enabled, attackers can overwrite existing site asset files (e.g., CSS, JS), potentially defacing or degrading the website. On Windows-hosted environments, the impact is elevated: planted files can be served publicly and existing files of the same type at the targeted path can be deleted, increasing the risk of content manipulation and data loss (WPScan).
The vulnerability is exploitable by unauthenticated attackers, requiring no credentials or special privileges. A proof-of-concept is being withheld until September 26, 2026, to allow time for users to update. The EPSS score is currently 0.0, and there is no confirmed evidence of in-the-wild exploitation or inclusion in the CISA KEV catalog at this time (WPScan, Feedly).
/wp-content/plugins/breeze/readme.txt.../../) to target a location outside the intended cache directory on the server./wp-content/cache/breeze/); modified or overwritten CSS/JS asset files in /wp-content/ or theme directories with timestamps inconsistent with legitimate deployments.../, %2e%2e%2f); repeated requests from a single IP targeting cache-related endpoints.wp-content/debug.log) showing file write operations to unexpected directories triggered by the Breeze Cache plugin (WPScan).Update the Breeze Cache WordPress plugin to version 2.5.13 or later, which contains the fix for this vulnerability. No configuration-based workaround has been published; upgrading is the only recommended remediation. Site administrators who cannot immediately update should consider temporarily disabling the Breeze Cache plugin and the optional asset optimization feature to reduce exposure (WPScan).
The vulnerability was discovered and reported by independent researcher Jakub Herman, who submitted it to WPScan. The disclosure follows a coordinated timeline, with the proof-of-concept withheld until September 26, 2026, to allow users time to patch. No significant vendor statements or broad media coverage have been identified beyond the WPScan advisory at this time (WPScan).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."