Breeze Cache WordPress plugin <= 2.4.4 contains an unrestricted file upload vulnerability caused by missing file type validation in 'fetch_gravatar_from_remote' function, letting unauthenticated attackers upload arbitrary files, exploit requires 'Host Files Locally - Gravatars' enabled.
id: CVE-2026-3844
info:
name: Breeze <= 2.4.4 - Arbitrary File Upload
author: theamanrawat,riti
...