Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/dhananjayasj/cve-2026-3844-breeze-cache-wordpress-plugin-remote-code-execution
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityLearning & EducationLabs & Practice
GitHubdhananjayasj/cve-2026-3844-breeze-cache-wordpress-plugin-remote-code-execution

CVE-2026-3844-Breeze-Cache-WordPress-Plugin-Remote-Code-Execution

Docker lab and manual exploitation guide for CVE-2026-3844, a critical unauthenticated arbitrary file upload vulnerability in the Breeze Cache WordPress plugin leading to remote code execution.

View Repository
143 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-3844 – Breeze Cache WordPress Plugin Unauthenticated RCE

CVE-2026-3844 CVSS WordPress License

CVE-2026-3844 is a critical unauthenticated arbitrary file upload vulnerability in the Breeze Cache WordPress plugin (versions ≤ 2.4.4). An attacker can post a comment containing a malicious `` tag pointing to a PHP web shell. The plugin fetches and stores the file in a publicly accessible cache directory (/wp-content/cache/breeze-extra/gravatars/), leading to Remote Code Execution (RCE).

This repository provides a fully functional Docker lab and a manual exploitation guide to reproduce the vulnerability safely.


📋 Table of Contents

  • Vulnerability Overview
  • Lab Environment (Docker)
  • Exploitation Steps
    • 1. Host the Payload
    • 2. Post Malicious Comment
    • 3. Verify Upload & Execute Commands
    • 4. Reverse Shell (Optional)
  • Mitigation & Remediation
  • Detection
  • References
  • Disclaimer

🧠 Vulnerability Overview

PropertyDetails
CVE IDCVE-2026-3844
CVSS Score9.8 (Critical) – AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNetwork – unauthenticated HTTP POST to /wp-comments-post.php
Affected SoftwareWordPress Breeze Cache plugin ≤ 2.4.4
Patched VersionBreeze Cache ≥ 2.4.5
Root CauseMissing file type validation in fetch_gravatar_from_remote() (CWE-434)
Prerequisite"Host Files Locally – Gravatars" option must be enabled in Breeze settings

How It Works

  1. The attacker hosts a PHP web shell (e.g., shell.php) on a public or local HTTP server.
  2. The attacker posts a comment on any WordPress post that has comments open, with the following payload:
Download Tool