Impact
The Breeze Cache WordPress plugin prior to version 2.5.6 contains a flaw in its HTML minification routine. The plugin uses a predictable replacement hash combined with a regular expression that captures attributes, enabling an unauthenticated attacker to inject arbitrary HTML attributes into the final page output. These injected attributes can be used to deliver malicious scripts or otherwise alter the rendered content.
Affected Systems
All installations of the Breeze Cache WordPress plugin older than 2.5.6 are vulnerable. The plugin is commonly used on WordPress sites to reduce page size and improve load times, so any site that has not migrated to version 2.5.6 or later may be affected.
Risk and Exploitability
The vulnerability can be exploited without authentication by accessing any page that triggers the minification process, which occurs during normal page rendering. The EPSS score of less than 1 % indicates that exploitation events are expected to be very rare, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS base score of 6.1 places the severity in the medium range. Because the flaw is a stored XSS, exploitation could compromise the confidentiality, integrity, or availability of site content or users who visit the affected pages.
OpenCVE Enrichment