CVE-2026-79713: Unknown Breeze Cache

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have a page rendered under their own request context stored under, and served from, the clean URL's cache entry to every subsequent visitor.

Affected products

  • Unknown Breeze Cache: from 1.2.5, before 2.5.15 (fixed in 2.5.15)

Published 2026-09-18. Last modified 2026-09-18.