CVE-2026-79713 Details
Description
The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have a page rendered under their own request context stored under, and served from, the clean URL's cache entry to every subsequent visitor.
A cache poisoning vulnerability has been identified in the Breeze Cache WordPress plugin, affecting versions prior to 2.5.15. The issue arises because the plugin does not incorporate certain tracking-related query parameters into its page-cache key, yet still caches pages that include these parameters. This oversight allows unauthenticated attackers to have pages rendered under their own request context, which are then stored and served from the clean URL's cache entry to subsequent visitors. If another component on the site reflects one of these parameters onto the page, it could result in stored Cross-Site Scripting that impacts all visitors to the affected URL.
Users are advised to update the Breeze Cache WordPress plugin to version 2.5.15 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 18, 2026CISA-ADP
Assessed Sep 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/7d62297b-40e3-445f-b970-9a34dcabd7c7/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Breeze Cache | >= 1.2.5, <= 2.5.14 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 18, 2026 | CVE Modified | CISA-ADP |
| Sep 18, 2026 | New CVE Received | [email protected] |
Volerion