Executive brief
Breeze Cache is a popular WordPress plugin used to speed up websites by optimizing how pages are loaded. A security flaw in the plugin's optimization process allows unauthorized attackers to inject malicious scripts into the website. This could lead to attackers stealing visitor data, hijacking administrator sessions, or defacing the site.
Technical details
The Breeze Cache plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) in versions prior to 2.5.6. The vulnerability stems from the HTML minification library, which uses a predictable replacement hash and an exploitable regular expression. By anticipating the placeholder format used during minification, an attacker can inject arbitrary HTML attributes into the final output. This allows for the execution of malicious scripts in the context of a user's browser. The issue is fixed in version 2.5.6.
Affected products
- Cloudways Breeze Cache < 2.5.6
Timeline
- 2026-06-22: disclosed
- 2026-07-13: advisory