CVE-2026-104006

Published: Ott 10, 2026 Last Modified: Ott 11, 2026
ExploitDB:
Other exploit source:
Google Dorks:
LOW 3,7
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none

Description

AI Translation Available

The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the 'comment_author_*, comment_author_email_*' parameter. This makes it possible for unauthenticated attackers to extract the full name and email address of returning commenters pre-filled into comment form input fields and persisted as the site-wide cached page by any unauthenticated attacker requesting the same public URL. The read-side handler in advanced-cache.php correctly skips cached delivery for requests carrying comment_author_* cookies, but this check is absent on the write path, meaning the cache poisoning is invisible to the victim commenter yet fully exploitable by any unauthenticated attacker with no cookies.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0026
Percentile
0,2th
Updated

EPSS Score Trend (Last 2 Days)

524

Use of Cache Containing Sensitive Information

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Application Data
Applicable Platforms
All platforms may be affected
View CWE Details
https://plugins.trac.wordpress.org/browser/speedycache/tags/1.4.2/main/advanced…
https://plugins.trac.wordpress.org/browser/speedycache/tags/1.4.2/main/cache.ph…
https://plugins.trac.wordpress.org/browser/speedycache/tags/1.4.2/main/cache.ph…
https://plugins.trac.wordpress.org/browser/speedycache/tags/1.4.2/main/cache.ph…
https://plugins.trac.wordpress.org/changeset/3734608/speedycache/trunk/main/cac…
https://plugins.trac.wordpress.org/changeset/3734609/speedycache
https://www.wordfence.com/threat-intel/vulnerabilities/id/c6b8d5ca-34e2-4d25-91…