{"id":"CVE-2026-10551","title":"The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression","summary":"The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allo…","severity":"none","published":"2026-07-13","updated":"2026-07-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-10551","references":[{"url":"https://wpscan.com/vulnerability/381fb82f-2fdc-49cb-bb0d-8d70ead61d86/","label":"contact@wpscan.com"}],"tags":["nvd"],"ingestedAt":"2026-07-13T07:25:22.630Z","epss":0.00253,"epssPercentile":0.14983,"slug":"CVE-2026-10551","body":"## Overview\n\nThe Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}