CVE-2026-104006Low· 3.7▾ SunlitThe SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the 'comment_author_*, comment_author_email_*' parameter. This makes …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the 'comment_author_, comment_author_email_' parameter. This makes it possible for unauthenticated attackers to extract the full name and email address of returning commenters pre-filled into comment form input fields and persisted as the site-wide cached page by any unauthenticated attacker requesting the same public URL. The read-side handler in advanced-cache.php correctly skips cached delivery for requests carrying comment_author_* cookies, but this check is absent on the write path, meaning the cache poisoning is invisible to the victim commenter yet fully exploitable by any unauthenticated attacker with no cookies.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-107851Medium· 4.3Contao is an Open Source CMS
CVE-2024-0874Medium· 5.3A flaw was found in coredns
CVE-2025-64762Critical· 9.1The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js
CVE-2025-43410Low· 2.4The issue was addressed with improved handling of caches
CVE-2025-64696Low· 3.3Android App "Brother iPrint&Scan" versions 6.13.7 and earlier improperly uses an external cache directory
CVE-2026-105752Low· 3.1vLLM is an inference and serving engine for large language models