CVE-2026-104006: SpeedyCache <= 1.4.2 - Unauthenticated Sensitive Information Exposure via Insecure Cache Configuration via Cache Write Gate Missing comment_author_* Cookie Check
The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the 'commentauthor, commentauthoremail' parameter. This makes it possible for unauthenticated attackers to extract the full name and email address of returning commenters pre-filled into comment form input fields and persisted as the site-wide cached page by any unauthenticated attacker requesting the same public URL. The read-side handler in advanced-cache.php correctly skips cached delivery for requests carrying commentauthor cookies, but this check is absent on the write path, meaning the cache poisoning is invisible to the victim commenter yet fully exploitable by any unauthenticated attacker with no cookies.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Sites using SpeedyCache versions through 1.4.2 are exposed when public pages with comment forms can be cached. Returning commenters whose names and email addresses are pre-filled from comment_author_* cookies are the data subjects at risk.
What does an attacker need to exploit it?
An attacker does not need authentication or user interaction. They need to request the same public URL after a returning commenter causes their pre-filled comment details to be written into the site-wide cache, then access that cached page without the relevant cookies.
Why might affected commenters not notice the problem?
The cache read handler skips cached delivery for requests containing comment_author_* cookies. As a result, the returning commenter may receive an uncached page while cookie-less visitors can receive the poisoned cached page containing the commenter’s full name and email address.
How can I determine whether information has been exposed?
Check cached public pages that contain comment forms using a request with no comment_author_* cookies, particularly after a known returning commenter visits the same URL. Exposure is indicated if the form displays a commenter’s pre-filled name or email address to a cookie-less visitor.