Description
The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the 'comment_author_*, comment_author_email_*' parameter. This makes it possible for unauthenticated attackers to extract the full name and email address of returning commenters pre-filled into comment form input fields and persisted as the site-wide cached page by any unauthenticated attacker requesting the same public URL. The read-side handler in advanced-cache.php correctly skips cached delivery for requests carrying comment_author_* cookies, but this check is absent on the write path, meaning the cache poisoning is invisible to the victim commenter yet fully exploitable by any unauthenticated attacker with no cookies.
Published: 2026-10-10
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: Sensitive Information Exposure
Action: Check for patch
AI Analysis

Impact

The SpeedyCache plugin for WordPress contains a flaw in its cache configuration that allows unauthenticated users to read cached pages containing personal data of returning commenters. The vulnerability is triggered by the absence of a check for the comment_author_* cookies during the cache write process, causing the cache to store pages that include the full name and email address pre‑filled into comment form input fields. The attacker can then retrieve this sensitive information on subsequently accessed public URLs without any authentication or user cookies.

Affected Systems

All installations of Softaculous SpeedyCache version 1.4.2 or earlier are affected. The flaw exists across all WordPress sites using this plugin up to version 1.4.2.

Risk and Exploitability

The flaw scores 3.7 on the CVSS scale, indicating a moderate severity. Because the exposure requires only an unauthenticated HTTP request to a public URL, the attack vector is straightforward and does not require user interaction. While the EPSS score is not available, the knowledge of the specific code paths makes exploitation likely for determined attackers. The vulnerability is not listed in the CISA KEV catalog, and there is currently no publicly available official fix, so administrators should monitor vendor notices for an update before implementation.

Generated by OpenCVE AI on October 10, 2026 at 08:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Verify the installed SpeedyCache version; if it is 1.4.2 or older, check the vendor’s website or plugin repository for any available updates that address the cache write cookie check.
  • While awaiting an official fix, manually modify advanced-cache.php (or the relevant cache handler) to add a comment_author_* cookie validation on the write path, or disable caching for pages that contain comment form fields.
  • Configure a security plugin or an .htaccess rule to block caching of comment form pages, thereby preventing the exposure of personal data from cached content.

Generated by OpenCVE AI on October 10, 2026 at 08:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the 'comment_author_*, comment_author_email_*' parameter. This makes it possible for unauthenticated attackers to extract the full name and email address of returning commenters pre-filled into comment form input fields and persisted as the site-wide cached page by any unauthenticated attacker requesting the same public URL. The read-side handler in advanced-cache.php correctly skips cached delivery for requests carrying comment_author_* cookies, but this check is absent on the write path, meaning the cache poisoning is invisible to the victim commenter yet fully exploitable by any unauthenticated attacker with no cookies.
Title SpeedyCache <= 1.4.2 - Unauthenticated Sensitive Information Exposure via Insecure Cache Configuration via Cache Write Gate Missing comment_author_* Cookie Check
Weaknesses CWE-524
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T06:40:15.885Z

Reserved: 2026-10-01T16:26:50.185Z

Link: CVE-2026-104006

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T07:16:40.410

Modified: 2026-10-10T07:16:40.410

Link: CVE-2026-104006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:00:03Z

Weaknesses
  • CWE-524

    Use of Cache Containing Sensitive Information