
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-79706 is an unauthenticated file creation vulnerability via cache path traversal in the Breeze Cache WordPress plugin by Cloudways. The flaw allows unauthenticated attackers to create files at arbitrary locations on the server, outside the intended cache directory. It affects all versions of the Breeze Cache plugin before 2.5.13. The vulnerability was publicly disclosed on August 26, 2026, and assigned by WPScan. The CVSS category is estimated as HIGH, though a precise numeric score has not yet been published (WPScan, Feedly).
The root cause is insufficient input sanitization of a user-supplied value from the HTTP request that is used to construct file cache paths (CWE-434: Unrestricted Upload of File with Dangerous Type / path traversal). An unauthenticated attacker can manipulate this value to traverse outside the intended cache directory and write files to arbitrary server locations. The file extension is constrained and file content is not attacker-controlled, limiting direct code execution risk; however, when the optional asset optimization feature is enabled, existing site asset files can be overwritten. On Windows hosts, the vulnerability additionally allows the planted file to be served publicly and an existing file of the same type at the targeted location to be deleted. A proof-of-concept is scheduled for public release on September 26, 2026 (WPScan).
Successful exploitation allows unauthenticated attackers to create files at arbitrary locations on the server, which can lead to disk consumption and potential disruption of site functionality. When the optional asset optimization feature is enabled, attackers can overwrite existing site asset files (e.g., CSS, JS), potentially defacing or degrading the website. On Windows-hosted environments, the impact is elevated: planted files can be served publicly and existing files of the same type at the targeted path can be deleted, increasing the risk of content manipulation and data loss (WPScan).
The vulnerability is exploitable by unauthenticated attackers, requiring no credentials or special privileges. A proof-of-concept is being withheld until September 26, 2026, to allow time for users to update. The EPSS score is currently 0.0, and there is no confirmed evidence of in-the-wild exploitation or inclusion in the CISA KEV catalog at this time (WPScan, Feedly).
/wp-content/plugins/breeze/readme.txt.../../) to target a location outside the intended cache directory on the server./wp-content/cache/breeze/); modified or overwritten CSS/JS asset files in /wp-content/ or theme directories with timestamps inconsistent with legitimate deployments.../, %2e%2e%2f); repeated requests from a single IP targeting cache-related endpoints.wp-content/debug.log) showing file write operations to unexpected directories triggered by the Breeze Cache plugin (WPScan).Update the Breeze Cache WordPress plugin to version 2.5.13 or later, which contains the fix for this vulnerability. No configuration-based workaround has been published; upgrading is the only recommended remediation. Site administrators who cannot immediately update should consider temporarily disabling the Breeze Cache plugin and the optional asset optimization feature to reduce exposure (WPScan).
The vulnerability was discovered and reported by independent researcher Jakub Herman, who submitted it to WPScan. The disclosure follows a coordinated timeline, with the proof-of-concept withheld until September 26, 2026, to allow users time to patch. No significant vendor statements or broad media coverage have been identified beyond the WPScan advisory at this time (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."