Sensitive Information Exposure in SpeedyCache Plugin for WordPress
CVE-2026-104006
3.7LOW
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-104006?
The SpeedyCache plugin for WordPress is susceptible to a vulnerability that allows unauthenticated attackers to access sensitive user information, specifically the names and email addresses of returning commenters. When users submit comments, their details can be extracted from the cached data if specific parameters are manipulated. Although the plugin implements checks to prevent access during read requests, these safeguards are bypassed during write operations. This oversight enables attackers to poison the cache and compromise user information without detection, as the affected commenters remain unaware of the exposure.
Affected Version(s)
SpeedyCache β Cache, Optimization, Performance 0 <= 1.4.2