CVE-2026-104006: SpeedyCache <= 1.4.2 - Unauthenticated Sensitive Information Exposure via Insecure Cache Configuration via Cache Write Gate Missing comment_author_* Cookie Check

Published Oct 10, 2026
·
Updated

The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the 'commentauthor, commentauthoremail' parameter. This makes it possible for unauthenticated attackers to extract the full name and email address of returning commenters pre-filled into comment form input fields and persisted as the site-wide cached page by any unauthenticated attacker requesting the same public URL. The read-side handler in advanced-cache.php correctly skips cached delivery for requests carrying commentauthor cookies, but this check is absent on the write path, meaning the cache poisoning is invisible to the victim commenter yet fully exploitable by any unauthenticated attacker with no cookies.

Affected Software

1 affected component
WordPress SpeedyCache – Cache, Optimization, Performance<=1.4.2

Event History

Oct 10, 2026
CVE Published
via MITRE·06:40 AM
Data Sourced
via MITRE·06:40 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Sites using SpeedyCache versions through 1.4.2 are exposed when public pages with comment forms can be cached. Returning commenters whose names and email addresses are pre-filled from comment_author_* cookies are the data subjects at risk.

2

What does an attacker need to exploit it?

An attacker does not need authentication or user interaction. They need to request the same public URL after a returning commenter causes their pre-filled comment details to be written into the site-wide cache, then access that cached page without the relevant cookies.

3

Why might affected commenters not notice the problem?

The cache read handler skips cached delivery for requests containing comment_author_* cookies. As a result, the returning commenter may receive an uncached page while cookie-less visitors can receive the poisoned cached page containing the commenter’s full name and email address.

4

How can I determine whether information has been exposed?

Check cached public pages that contain comment forms using a request with no comment_author_* cookies, particularly after a known returning commenter visits the same URL. Exposure is indicated if the form displays a commenter’s pre-filled name or email address to a cookie-less visitor.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203