Description
Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.
Published: 2026-08-18
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to delete any content managed by the Breeze plugin on a WordPress site. Because the plugin lacks proper access control, attackers can remove pages, posts, or other data, causing integrity loss and potential site downtime. This represents a high‑impact integrity and availability violation, mapped to CWE-862.

Affected Systems

WordPress sites that use the Cloudways Breeze plugin version 2.5.12 or earlier are affected. Any installation of Breeze <= 2.5.12, regardless of WordPress version, can be exploited because the deletion flaw exists in the plugin’s core code. Administrators should check the plugin version on all sites and verify that they are running 2.5.13 or later.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity. The EPSS score is not available, but the vulnerability is not listed in CISA’s KEV catalog, implying no publicly known exploitation yet. Because the flaw is unauthenticated, an attacker with network access to the site could trigger a deletion via crafted HTTP requests, potentially without any legitimate user credentials. The absence of a defined workaround suggests that the primary defense is to apply the vendor‑issued patch.

Generated by OpenCVE AI on August 18, 2026 at 16:20 UTC.

Remediation

Vendor Solution

Update the WordPress Breeze Plugin to the latest available version (at least 2.5.13).


OpenCVE Recommended Actions

  • Update the Breeze plugin to version 2.5.13 or newer to remove the deletion flaw.
  • Delete or rename any residual Breeze files from earlier versions that may still reside on the server to prevent re‑introduction.
  • Restrict content deletion permissions by adjusting WordPress roles or using a security plugin to grant delete capability only to trusted administrators.

Generated by OpenCVE AI on August 18, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.
Title WordPress Breeze plugin <= 2.5.12 - Arbitrary Content Deletion vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T14:51:00.213Z

Reserved: 2026-08-12T10:51:20.621Z

Link: CVE-2026-73356

cve-icon Vulnrichment

Updated: 2026-08-18T14:50:55.660Z

cve-icon NVD

Status : Received

Published: 2026-08-18T15:17:03.940

Modified: 2026-08-18T15:17:03.940

Link: CVE-2026-73356

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T16:30:05Z

Weaknesses