An unauthenticated arbitrary file upload vulnerability in the Breeze Cache plugin for WordPress allows attackers to drop a PHP webshell onto the server through the plugin’s Gravatar-fetching function, leading to remote code execution on affected sites.
Read more about Emerging Threat: (CVE-2026-3844) WordPress Breeze Cache Plugin Unauthenticated File Upload