A widely installed WordPress cache plugin is turning sites into file-drop targets. The flaw is unauthenticated, so the standard assumption that only logged-in users can change server files does not hold here. Active exploitation means exposed sites can move from a plugin bug to webshell risk fast.
CVE-2026-3844 affects Breeze Cache versions up to and including 2.4.4, with Cloudways fixing it in 2.4.5. Wordfence says it has already seen more than 170 exploitation attempts, and the plugin has more than 400,000 active installations. Exploitation depends on the optional “Host Files Locally - Gravatars” add-on being enabled, which narrows exposure but does not reduce the severity for sites that use it.
The practical risk is not just file upload. Once arbitrary files can land on the server, attackers can pivot to website takeover on affected WordPress installs, and patching only helps if the vulnerable add-on path is removed from use.