Extension WordPress
Vulnérabilités Breeze Cache
Cette page rassemble les failles publiées pour Breeze Cache, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Breeze Cache
10 fiches
Breeze Cache <= 2.5.2 – Unauthenticated Exposure of Sensitive Information to an Unauthorized Actor via Crafted Login Cookie
The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versions up to, and including, 2.5.2 This is due to improper verification of the `wordpress_logged_in_` cookie in the `inc/cache/execute-cache.php` file…
*-2.5.2
2.5.3
28/05/2026
Breeze Cache <= 2.4.4 – Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to…
*-2.4.4
2.4.5
22/04/2026
Breeze – WordPress Cache Plugin <= 2.2.21 – Missing Authorization to Cache Deletion
The Breeze – WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized cache clearing in all versions up to, and including, 2.2.21. This is due to the REST API endpoint `/wp-json/breeze/v1/clear-all-cache` being registered with `permission_callback => '__return_true'`…
*-2.2.21
2.2.22
18/02/2026
Breeze <= 2.2.21 – Missing Authorization
The Breeze Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.21. This makes it possible for unauthenticated attackers to perform an…
*-2.2.21
2.2.22
13/01/2026
Breeze <= 2.2.13 – Missing Authorization
The Breeze – WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.13. This makes it possible for authenticated attackers,…
*-2.2.13
2.2.14
18/06/2025
Breeze <= 2.1.14 – Missing Authorization
The Breeze plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_to_default() function in versions up to, and including, 2.1.14. This makes it possible for unauthenticated attackers to reset…
*-2.1.14
2.1.15
24/10/2024
Breeze <= 2.1.14 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Breeze plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above,…
*-2.1.14
2.1.15
24/10/2024
Breeze <= 2.1.3 – Authenticated (Administrator+) Stored Cross-Site Scripting via breeze_api_token
The Breeze plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘breeze_api_token’ parameter in versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-2.1.3
2.1.4
25/03/2024
Breeze <= 2.0.8 – Cross-Site Request Forgery via import_json_settings
The Breeze plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.8. This is due to missing or incorrect nonce validation on the 'import_json_settings' function. This makes it possible for unauthenticated attackers…
*-2.0.8
2.0.9
19/09/2022
Breeze – WordPress Cache Plugin <= 2.0.2 – Unprotected AJAX Actions
Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability in Cloudways Breeze plugin
*-2.0.2
2.0.3
02/05/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.