Security Advisory
CVE-2026-10551
6.1
MEDIUM
Vulnerability Description
The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.
Published Date
July 13, 2026
Official Source
NIST NVD Advisory