CVE-2026-104006
Received Received - Intake

Sensitive Information Exposure in SpeedyCache WordPress Plugin

Vulnerability report for CVE-2026-104006, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the 'comment_author_*, comment_author_email_*' parameter. This makes it possible for unauthenticated attackers to extract the full name and email address of returning commenters pre-filled into comment form input fields and persisted as the site-wide cached page by any unauthenticated attacker requesting the same public URL. The read-side handler in advanced-cache.php correctly skips cached delivery for requests carrying comment_author_* cookies, but this check is absent on the write path, meaning the cache poisoning is invisible to the victim commenter yet fully exploitable by any unauthenticated attacker with no cookies.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
softaculous SpeedyCache – Cache, Optimization, Performance 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-524 The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The SpeedyCache WordPress plugin up to version 1.4.2 has a vulnerability where unauthenticated attackers can access sensitive information like full names and email addresses of commenters. This happens because cached pages store comment form data, including pre-filled details, which attackers can retrieve by requesting the same public URL.

Detection Guidance

Check WordPress sites using SpeedyCache plugin versions up to 1.4.2. Inspect cached pages for exposed comment_author_* or comment_author_email_* data. Use curl to fetch cached pages and look for pre-filled comment form fields with user data.

Impact Analysis

If you use this plugin, attackers could steal personal data of commenters without needing access to your site. This could lead to privacy breaches, spam targeting commenters, or reputational damage for your website.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data without consent. For HIPAA, if commenters include health-related details, it may breach protected health information rules. Organizations must address this to avoid legal penalties.

Mitigation Strategies

Update SpeedyCache plugin to the latest version. Disable caching for comment forms or exclude pages with comment forms from caching. Review cached pages to remove any exposed sensitive data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104006. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart