SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-10551

MEDIUM · CVSS 6.1 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The Breeze Cache WordPress plugin prior to version 2.5.6 is susceptible to unauthenticated Stored Cross-Site Scripting (XSS) due to a flaw in its HTML minification process. This vulnerability enables attackers to inject arbitrary HTML attributes into the final output, potentially compromising the integrity of the website. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-10551
Severity
MEDIUM
CVSS
6.1
EPSS
0.15%
WordPress

Original NVD Description

The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.