CVE-2026-2128
The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versions up to, and including, 2.5.2 This is due to improper verification of the `wordpress_logged_in_` cookie in the `inc/cache/execute-cache.php` file when the "Cache Logged-in Users" setting is enabled. The plugin parses the username directly from the cookie value (e.g., `username|hash`) using `substr()` to retrieve the corresponding cache file but fails to verify the session's cryptographic signature or validity with WordPress core.
Leer descripción completaMostrar menos
This makes it possible for unauthenticated attackers to supply a crafted cookie (e.g., `wordpress_logged_in_fake=admin|fake`) to trick the plugin into serving the cached HTML content generated for an administrator, leading to the disclosure of sensitive information such as private posts (including their full content), the Admin Bar, WordPress nonces, and other data visible only to logged-in administrators or other users.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.27%
- Percentil entre todas las CVEs puntuadas: 18
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-200
Referencias
- https://plugins.trac.wordpress.org/browser/breeze/tags/2.2.24/inc/cache/execute-cache.php#L132
- https://plugins.trac.wordpress.org/browser/breeze/tags/2.2.24/inc/cache/execute-cache.php#L140
- https://plugins.trac.wordpress.org/browser/breeze/trunk/inc/cache/execute-cache.php#L140
- https://plugins.trac.wordpress.org/changeset/3456822/breeze/trunk/inc/cache/execute-cache.php
- https://plugins.trac.wordpress.org/changeset?old_path=%2Fbreeze/tags/2.2.24&new_path=%2Fbreeze/tags/2.3.0
- https://plugins.trac.wordpress.org/changeset?old_path=%2Fbreeze/tags/2.5.2&new_path=%2Fbreeze/tags/2.5.3
- https://www.wordfence.com/threat-intel/vulnerabilities/id/f0b6c41d-833e-4ad4-bdb6-c38fef3eb7f4?source=cve
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-2128",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-2128",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-29T10:02:35.493268Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@wordfence.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@wordfence.com",
"affectedData": [
{
"vendor": "cloudways",
"product": "Breeze Cache",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "2.5.2"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-05-29T05:16:19.267",
"references": [
{
"url": "https://plugins.trac.wordpress.org/browser/breeze/tags/2.2.24/inc/cache/execute-cache.php#L132",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/browser/breeze/tags/2.2.24/inc/cache/execute-cache.php#L140",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/browser/breeze/trunk/inc/cache/execute-cache.php#L140",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3456822/breeze/trunk/inc/cache/execute-cache.php",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fbreeze/tags/2.2.24&new_path=%2Fbreeze/tags/2.3.0",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fbreeze/tags/2.5.2&new_path=%2Fbreeze/tags/2.5.3",
"source": "security@wordfence.com"
},
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f0b6c41d-833e-4ad4-bdb6-c38fef3eb7f4?source=cve",
"source": "security@wordfence.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security@wordfence.com",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versions up to, and including, 2.5.2 This is due to improper verification of the `wordpress_logged_in_` cookie in the `inc/cache/execute-cache.php` file when the \"Cache Logged-in Users\" setting is enabled. The plugin parses the username directly from the cookie value (e.g., `username|hash`) using `substr()` to retrieve the corresponding cache file but fails to verify the session's cryptographic signature or validity with WordPress core. This makes it possible for unauthenticated attackers to supply a crafted cookie (e.g., `wordpress_logged_in_fake=admin|fake`) to trick the plugin into serving the cached HTML content generated for an administrator, leading to the disclosure of sensitive information such as private posts (including their full content), the Admin Bar, WordPress nonces, and other data visible only to logged-in administrators or other users."
},
{
"lang": "es",
"value": "El plugin Breeze para WordPress es vulnerable a la Exposición de Información Sensible a un Actor No Autorizado en todas las versiones hasta la 2.5.2, inclusive. Esto se debe a una verificación incorrecta de la cookie 'wordpress_logged_in_' en el archivo 'inc/cache/execute-cache.php' cuando la configuración 'Cache Logged-in Users' está habilitada. El plugin analiza el nombre de usuario directamente del valor de la cookie (p. ej., 'username|hash') utilizando 'substr()' para recuperar el archivo de caché correspondiente, pero no verifica la firma criptográfica o la validez de la sesión con el núcleo de WordPress. Esto permite a atacantes no autenticados proporcionar una cookie manipulada (p. ej., 'wordpress_logged_in_fake=admin|fake') para engañar al plugin y que sirva el contenido HTML en caché generado para un administrador, lo que lleva a la divulgación de información sensible como publicaciones privadas (incluido su contenido completo), la barra de administración, los nonces de WordPress y otros datos visibles solo para administradores u otros usuarios con sesión iniciada."
}
],
"lastModified": "2026-07-21T12:10:00.090",
"sourceIdentifier": "security@wordfence.com"
}