Impact
The Breeze Cache WordPress plugin before version 2.5.13 fails to sanitize a value extracted from the HTTP request before constructing the file paths it uses for caching. This omission permits an unauthenticated attacker to supply a crafted value that resolves to any directory outside the intended cache location, enabling creation of arbitrary files on the server. The result is a critical loss of integrity and, if the attacker controls the content of the written file, possible compromise of the site through stored malicious code or scripts.
Affected Systems
WordPress installations that have the Breeze Cache plugin installed with a version older than 2.5.13. The vulnerability does not target the core WordPress software but the plugin itself.
Risk and Exploitability
Attackers can exploit this flaw without authentication simply by sending a special request to the plugin’s endpoint. With no EPSS value provided and the issue not listed in CISA KEV, the probability of widespread exploitation is unknown, yet the impact of successful exploitation is severe. The lack of an official patch or workaround in the public data means a fresh deployment of a secure version is the only reliable mitigation path.
OpenCVE Enrichment