Sensitive Information Exposure in SpeedyCache Plugin for WordPress
CVE-2026-104006

3.7LOW

What is CVE-2026-104006?

The SpeedyCache plugin for WordPress is susceptible to a vulnerability that allows unauthenticated attackers to access sensitive user information, specifically the names and email addresses of returning commenters. When users submit comments, their details can be extracted from the cached data if specific parameters are manipulated. Although the plugin implements checks to prevent access during read requests, these safeguards are bypassed during write operations. This oversight enables attackers to poison the cache and compromise user information without detection, as the affected commenters remain unaware of the exposure.

Affected Version(s)

SpeedyCache – Cache, Optimization, Performance 0 <= 1.4.2

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kuba
.