The Breeze Cache WordPress plugin before 2.5.15 does not properly handle tracking-related query parameters in its page-cache key, potentially allowing unauthenticated attackers to serve cached pages under their own request context. This could lead to unauthorized serving of cached content and potential exposure of sensitive information. WordPress administrators and security teams should assess exposure an [truncated]
The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format. Users of Breeze Cache WordPress plugin versions before [truncated]