Sploitus

Exploit for CVE-2026-3844

kitploit · 2026-08-27

Exploit Code

MARKDOWN22 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-ANGGATECHI-CVE-2026-3844
![CVE-2026-3844](https://img.shields.io/badge/CVE-2026--3844-critical-red?style=for-the-badge) ![CVSS 9.8](https://img.shields.io/badge/CVSS-9.8-red?style=for-the-badge) ![CWE-434](https://img.shields.io/badge/CWE-434-orange?style=for-the-badge) ![WordPress Breeze Cache](https://img.shields.io/badge/WordPress-Breeze%20Cache-blue?style=for-the-badge&logo=wordpress) ![Unauthenticated](https://img.shields.io/badge/Auth-Unauthenticated-dc143c?style=for-the-badge)

  
  


root@kitploit:~
    
    
    ╔════════════════════════════════════════════════════════════╗
    ║ CVE-2026-3844                                             ║
    ║ Breeze Cache <= 2.4.4 Arbitrary File Upload               ║
    ║ Unauthenticated RCE | Authorized Lab Use Only              ║
    ╚════════════════════════════════════════════════════════════╝
    

* * *

## Обзор

`CVE-2026-3844` — это уязвимость произвольной загрузки файлов, затрагивающая уязвимые версии плагина **Breeze Cache** для WordPress. Когда включено локальное хранение Gravatar, Breeze может получать URL-адреса аватаров и сохранять загруженный файл в доступный через веб каталог кэша без достаточной проверки типа файла.