CVE-2026-2128
- EPSS 0.27%
- Veröffentlicht 29.05.2026 03:39:08
- Zuletzt bearbeitet 29.05.2026 13:09:05
The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versions up to, and including, 2.5.2 This is due to improper verification of the `wordpress_logged_in_` cookie in the `inc/cache/execut...
CVE-2026-3844
- EPSS 36.51%
- Veröffentlicht 23.04.2026 02:25:21
- Zuletzt bearbeitet 23.04.2026 14:28:55
The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated att...
CVE-2025-69364
- EPSS 0.23%
- Veröffentlicht 06.01.2026 16:36:42
- Zuletzt bearbeitet 27.04.2026 21:16:25
Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n/a through <= 2.2.21.
CVE-2025-23999
- EPSS 0.23%
- Veröffentlicht 18.06.2025 09:26:29
- Zuletzt bearbeitet 23.04.2026 15:24:56
Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n/a through <= 2.2.13.
CVE-2024-50422
- EPSS 0.54%
- Veröffentlicht 29.10.2024 22:15:04
- Zuletzt bearbeitet 23.04.2026 15:19:55
Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n/a through <= 2.1.14.
CVE-2024-50431
- EPSS 0.25%
- Veröffentlicht 28.10.2024 19:15:14
- Zuletzt bearbeitet 23.04.2026 15:19:56
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cloudways Breeze breeze allows Stored XSS.This issue affects Breeze: from n/a through <= 2.1.14.
CVE-2024-27188
- EPSS 0.34%
- Veröffentlicht 27.03.2024 07:15:49
- Zuletzt bearbeitet 23.04.2026 15:18:05
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cloudways Breeze breeze.This issue affects Breeze: from n/a through <= 2.1.3.
CVE-2022-29444
- EPSS 0.53%
- Veröffentlicht 02.05.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:06
Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability in Cloudways Breeze plugin <= 2.0.2 on WordPress allows users with a subscriber or higher user role to execute any of the wp_ajax_* actions in the class Breeze_Configuration w...