CVE-2026-104006 PUBLISHED

SpeedyCache <= 1.4.2 - Unauthenticated Sensitive Information Exposure via Insecure Cache Configuration via Cache Write Gate Missing comment_author_* Cookie Check

Assigner: Wordfence
Reserved: 01.10.2026 Published: 10.10.2026 Updated: 10.10.2026

The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the 'comment_author_, comment_author_email_' parameter. This makes it possible for unauthenticated attackers to extract the full name and email address of returning commenters pre-filled into comment form input fields and persisted as the site-wide cached page by any unauthenticated attacker requesting the same public URL. The read-side handler in advanced-cache.php correctly skips cached delivery for requests carrying comment_author_* cookies, but this check is absent on the write path, meaning the cache poisoning is invisible to the victim commenter yet fully exploitable by any unauthenticated attacker with no cookies.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 3.7

Product Status

Vendor softaculous
Product SpeedyCache – Cache, Optimization, Performance
Versions Default: unaffected
  • affected from 0 to 1.4.2 (incl.)

Credits

  • Kuba finder

References

Problem Types

  • CWE-524 Use of Cache Containing Sensitive Information CWE