CVE-2026-73356: WordPress Breeze plugin <= 2.5.12 - Arbitrary Content Deletion vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.
Affected Software
1 affected component
WordPress Breeze plugin<=2.5.12
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Breeze pluginto a version that resolves this vulnerability.Fixed in 2.5.13
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this vulnerability?
Sites running the WordPress Breeze plugin version 2.5.12 or earlier are affected. The issue is unauthenticated, so an attacker does not need a WordPress account or prior privileges.
2
What can be done if an update is not immediately available?
The provided data identifies the affected range as Breeze versions 2.5.12 and earlier, but does not provide a fixed version or mitigation. If patching is not immediately possible, the available data does not specify a supported workaround.