Description
The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.
Published: 2026-07-13
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Breeze Cache WordPress plugin prior to version 2.5.6 contains a flaw in its HTML minification routine. The plugin uses a predictable replacement hash combined with a regular expression that captures attributes, enabling an unauthenticated attacker to inject arbitrary HTML attributes into the final page output. These injected attributes can be used to deliver malicious scripts or otherwise alter the rendered content.

Affected Systems

All installations of the Breeze Cache WordPress plugin older than 2.5.6 are vulnerable. The plugin is commonly used on WordPress sites to reduce page size and improve load times, so any site that has not migrated to version 2.5.6 or later may be affected.

Risk and Exploitability

The vulnerability can be exploited without authentication by accessing any page that triggers the minification process, which occurs during normal page rendering. The EPSS score of less than 1 % indicates that exploitation events are expected to be very rare, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS base score of 6.1 places the severity in the medium range. Because the flaw is a stored XSS, exploitation could compromise the confidentiality, integrity, or availability of site content or users who visit the affected pages.

Generated by OpenCVE AI on August 3, 2026 at 03:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Breeze Cache to version 2.5.6 or later
  • If an immediate upgrade is not possible, disable the minification feature in the plugin’s settings to eliminate the predictable hash mechanism
  • Implement a strict content‑security policy that prevents inline scripts and limits allowed attributes to reduce the impact of any residual XSS content

Generated by OpenCVE AI on August 3, 2026 at 03:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 25 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Thu, 23 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Mon, 20 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Thu, 16 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Tue, 14 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.
Title Breeze Cache < 2.5.6 - Unauthenticated Stored XSS via Minify Library
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-13T15:54:20.284Z

Reserved: 2026-06-01T13:52:35.184Z

Link: CVE-2026-10551

cve-icon Vulnrichment

Updated: 2026-07-13T15:54:14.936Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T04:00:13Z

Weaknesses

No weakness.