Extension WordPress

Vulnérabilités Breeze Cache

Cette page rassemble les failles publiées pour Breeze Cache, leurs plages de versions affectées et les correctifs signalés dans la base locale.

10Vulnérabilités
1Critiques
10Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Breeze Cache

10 fiches

CVE-2026-2128 Moyenne · 5,3
Breeze Cache

Breeze Cache <= 2.5.2 – Unauthenticated Exposure of Sensitive Information to an Unauthorized Actor via Crafted Login Cookie

The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versions up to, and including, 2.5.2 This is due to improper verification of the `wordpress_logged_in_` cookie in the `inc/cache/execute-cache.php` file…

Versions affectées

*-2.5.2

Correctif

2.5.3

Publication

28/05/2026

CVE-2025-13864 Moyenne · 5,3
Breeze Cache

Breeze – WordPress Cache Plugin <= 2.2.21 – Missing Authorization to Cache Deletion

The Breeze – WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized cache clearing in all versions up to, and including, 2.2.21. This is due to the REST API endpoint `/wp-json/breeze/v1/clear-all-cache` being registered with `permission_callback => '__return_true'`…

Versions affectées

*-2.2.21

Correctif

2.2.22

Publication

18/02/2026

CVE-2025-69364 Moyenne · 5,3
Breeze Cache

Breeze <= 2.2.21 – Missing Authorization

The Breeze Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.21. This makes it possible for unauthenticated attackers to perform an…

Versions affectées

*-2.2.21

Correctif

2.2.22

Publication

13/01/2026

CVE-2025-23999 Moyenne · 4,3
Breeze Cache

Breeze <= 2.2.13 – Missing Authorization

The Breeze – WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.13. This makes it possible for authenticated attackers,…

Versions affectées

*-2.2.13

Correctif

2.2.14

Publication

18/06/2025

CVE-2024-50422 Moyenne · 5,3
Breeze Cache

Breeze <= 2.1.14 – Missing Authorization

The Breeze plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_to_default() function in versions up to, and including, 2.1.14. This makes it possible for unauthenticated attackers to reset…

Versions affectées

*-2.1.14

Correctif

2.1.15

Publication

24/10/2024

CVE-2024-27188 Moyenne · 5,5
Breeze Cache

Breeze <= 2.1.3 – Authenticated (Administrator+) Stored Cross-Site Scripting via breeze_api_token

The Breeze plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘breeze_api_token’ parameter in versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-2.1.3

Correctif

2.1.4

Publication

25/03/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités