CVE-2026-3844 — cloudways Breeze Cache
As of 2026-04-23, CVE-2026-3844 is a CRITICAL-severity vulnerability in cloudways Breeze Cache, CVSS v3.1 9.8, EPSS 36.5% (98.3th percentile). Threadlinqs Intelligence links 2 tracked threat campaigns to CVE-2026-3844, most recently “Australia (ACSC) Warns of Global Campaign Exploiting Vulnerable CMS Platforms to Deploy Webshells”.
Last updated: 2026-04-23
What is CVE-2026-3844?
The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if "Host Files Locally - Gravatars" is enabled, which is disabled by default.
The record classifies CVE-2026-3844 under weakness class CWE-434. Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs no prior authentication, needs no user interaction, and has high impact on confidentiality, integrity, availability. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 143 days ago.
Severity and exploitation probability
- CVSS v3.1 base score
- 9.8 — CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS (FIRST)
- 36.5% probability of exploitation in the next 30 days, higher than 98.3% of all scored CVEs
- CISA KEV
- Not listed in the CISA Known Exploited Vulnerabilities catalog
- Threadlinqs priority
- 10/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
- Published
- 2026-04-23
Is CVE-2026-3844 being exploited?
Weaponised exploit code for CVE-2026-3844 is publicly available. 2 public proof-of-concept repositories are tracked for this identifier. A ProjectDiscovery Nuclei detection template exists (http/cves/2026/CVE-2026-3844.yaml).
- rootdirective-sec/CVE-2026-3844-Lab (github)
- Dhananjayasj/CVE-2026-3844-Breeze-Cache-WordPress-Plugin-Remote-Code-Execution (github)
Affected products and versions
- cloudways: Breeze Cache
How to fix CVE-2026-3844
No vendor patch reference has been recorded for CVE-2026-3844 in the tracked sources. Follow the references below for a fix, and treat the products listed above as exposed until the vendor states otherwise.
Threat activity tracking CVE-2026-3844
2 tracked threats in the Threadlinqs corpus reference CVE-2026-3844, either in the campaign’s CVE list or as an indicator on the campaign record.
- Australia (ACSC) Warns of Global Campaign Exploiting Vulnerable CMS Platforms to Deploy Webshells — CRITICAL · 2026-07-11
- WP-SHELLSTORM: Exposed Chinese-Speaking Threat Actor Server Reveals Mass WordPress/Joomla Webshell Brokerage Targeting 1.4M Domains via CVE-2026-48907 (Joomla JCE) and CVE-2021-29441 (Nacos) — HIGH · 2026-07-10
Sources
Enriched from CVE.org, NVD, FIRST EPSS, GitHub Security Advisories, public proof-of-concept repositories, ProjectDiscovery Nuclei. Last verified by Threadlinqs on . This product uses the NVD API but is not endorsed or certified by the NVD.
Other references
- wordfence.com
- plugins.trac.wordpress.org
- plugins.trac.wordpress.org (class breeze cache cronjobs)
- plugins.trac.wordpress.org (breeze)
← all vulnerabilities · Markdown version · Threadlinqs Intelligence