Impact
The SpeedyCache plugin for WordPress contains a flaw in its cache configuration that allows unauthenticated users to read cached pages containing personal data of returning commenters. The vulnerability is triggered by the absence of a check for the comment_author_* cookies during the cache write process, causing the cache to store pages that include the full name and email address pre‑filled into comment form input fields. The attacker can then retrieve this sensitive information on subsequently accessed public URLs without any authentication or user cookies.
Affected Systems
All installations of Softaculous SpeedyCache version 1.4.2 or earlier are affected. The flaw exists across all WordPress sites using this plugin up to version 1.4.2.
Risk and Exploitability
The flaw scores 3.7 on the CVSS scale, indicating a moderate severity. Because the exposure requires only an unauthenticated HTTP request to a public URL, the attack vector is straightforward and does not require user interaction. While the EPSS score is not available, the knowledge of the specific code paths makes exploitation likely for determined attackers. The vulnerability is not listed in the CISA KEV catalog, and there is currently no publicly available official fix, so administrators should monitor vendor notices for an update before implementation.
OpenCVE Enrichment