Breeze Cache < 2.5.13 - Unauthenticated File Creation via Cache Path Traversal
Summary
| CVE | CVE-2026-79706 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-28 08:16:42 UTC |
| Updated | 2026-08-28 08:16:42 UTC |
| Description | The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to build the paths of the files it caches, allowing unauthenticated attackers to create files at arbitrary locations on the server, outside the intended cache directory. |
Risk And Classification
Problem Types: CWE-434 Unrestricted Upload of File with Dangerous Type
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | Breeze Cache | affected 2.5.13 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/c7086680-71ee-4520-9c21-d510b2ec92b4 | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Jakub Herman (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.