
Docker lab and manual exploitation guide for CVE-2026-3844, a critical unauthenticated arbitrary file upload vulnerability in the Breeze Cache WordPress plugin leading to remote code execution.
CVE-2026-3844 is a critical unauthenticated arbitrary file upload vulnerability in the Breeze Cache WordPress plugin (versions ≤ 2.4.4). An attacker can post a comment containing a malicious `` tag pointing to a PHP web shell. The plugin fetches and stores the file in a publicly accessible cache directory (/wp-content/cache/breeze-extra/gravatars/), leading to Remote Code Execution (RCE).
This repository provides a fully functional Docker lab and a manual exploitation guide to reproduce the vulnerability safely.
| Property | Details |
|---|---|
| CVE ID | CVE-2026-3844 |
| CVSS Score | 9.8 (Critical) – AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Attack Vector | Network – unauthenticated HTTP POST to /wp-comments-post.php |
| Affected Software | WordPress Breeze Cache plugin ≤ 2.4.4 |
| Patched Version | Breeze Cache ≥ 2.4.5 |
| Root Cause | Missing file type validation in fetch_gravatar_from_remote() (CWE-434) |
| Prerequisite | "Host Files Locally – Gravatars" option must be enabled in Breeze settings |
shell.php) on a public or local HTTP server.