Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities SC Media

Critical vulnerability in WordPress Breeze Cache plugin exploited

A critical vulnerability (CVE-2026-3844, CVSS 9.8) in the WordPress Breeze Cache plugin allows unauthenticated attackers to upload arbitrary files via a missing file-type validation in the `fetch_gravatar_from_remote` function, potentially leading to remote code execution. The flaw affects all versions up to and including 2.4.4 and is actively exploited. Administrators must upgrade to the patched version 2.4.5 immediately or, if not possible, disable the non-default "Host Files Locally - Gravatars" add-on.
Read Full Article →

Vulnerability Management , Patch/Configuration Management Critical vulnerability in WordPress Breeze Cache plugin exploited April 24, 2026 Share By SC Staff Hackers are actively exploiting a critical vulnerability in the Breeze Cache plugin for WordPress, allowing for unauthenticated arbitrary file uploads. This security issue, tracked as CVE-2026-3844, has been observed in over 170 exploitation attempts. The Breeze Cache plugin, used by more than 400,000 active installations, is designed to enhance website performance through caching and optimization, as reported by Bleeping Computer. The vulnerability, with a critical severity score of 9.8 out of 10, stems from a missing file-type validation in the "fetch_gravatar_from_remote" function. This flaw enables unauthenticated attackers to upload arbitrary files to the server, potentially leading to remote code execution and complete website takeover. However, successful exploitation requires the "Host Files Locally - Gravatars" add-on to be enabled, which is not the default setting. The vulnerability affects all Breeze Cache versions up to and including 2.4.4, with a fix released in version 2.4.5. Given the active exploitation, website administrators using the Breeze Cache plugin are strongly advised to upgrade to version 2.4.5 immediately or, at a minimum, disable the "Host Files Locally - Gravatars" feature if an upgrade is not immediately feasible. Source: Bleeping Computer SC Staff Related Vulnerability Management Actively exploited SharePoint spoofing bug continues to threaten over 1,300 instances SC Staff April 23, 2026 More than 1,300 internet-exposed Microsoft SharePoint servers remain vulnerable to ongoing intrusions weaponizing the zero-day spoofing flaw, tracked as CVE-2026-32201, while fewer than 200 online SharePoint instances have been fixed since last week's Patch Tuesday release, BleepingComputer reports. Vulnerability Management Discontinued D-Link routers subjected to Mirai botnet targeting SC Staff April 23, 2026 Security Affairs reports that vulnerable end-of-life D-Link DIR-823X routers impacted by the command injection flaw, tracked as CVE-2025-29635, have been targeted by Mirai botnet intrusions since early March, or about a year after the security issue was initially disclosed. Vulnerability Management Microsoft patches critical ASP.NET Core privilege escalation vulnerability SC Staff April 23, 2026 The vulnerability stems from a regression in specific versions of the Microsoft.AspNetCore.DataProtection NuGet packages. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds

Share this article