Security Advisory

CVE-2026-10551

6.1
MEDIUM

Vulnerability Description

The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.
Published Date July 13, 2026
Official Source NIST NVD Advisory