← WordPress Vulnerabilities
WordPress security by component

SpeedyCache – Cache, Optimization, Performance

SpeedyCache – Cache, Optimization, Performance is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 5.4.

Plugin slug: speedycache

CVE-2026-5114: SpeedyCache administrator path traversal exposes server files through public cache files

SpeedyCache through 1.3.8 is vulnerable to arbitrary file read when an Administrator injects a crafted stylesheet link into page content. CSS::combine() accepts a URL when its full value contains a .css suffix, including a .css marker placed in the query portion. Util::url_to_path() then removes everything from the first question mark onward without confirming the resolved path remains inside WordPress or points to a CSS file. The resulting path is passed to file_get_contents(), and its contents are written into a publicly accessible combined-CSS cache file. This permits disclosure of files such as wp-config.php and /etc/passwd. Version 1.3.9 resolves and confines the path to the WordPress installation and requires the resolved file to have the expected CSS extension. The specific HTTP endpoint used to place the crafted content is not identified by the CNA or upstream release note.

PublishedJul 28, 2026
Known safe version1.3.9
Safe version
Jul 28, 2026 CVE-2026-5114
SpeedyCache administrator path traversal exposes server files through public cache files
SpeedyCache through 1.3.8 is vulnerable to arbitrary file read when an Administrator injects a crafted stylesheet link into page content. CSS::combine() accepts a URL when its full value contains a .css suffix, including a .css marker placed in the query portion. Util::url_to_path() then removes everything from the first question mark onward without confirming the resolved path remains inside WordPress or points to a CSS file. The resulting path is passed to file_get_contents(), and its contents are written into a publicly accessible combined-CSS cache file. This permits disclosure of files such as wp-config.php and /etc/passwd. Version 1.3.9 resolves and confines the path to the WordPress installation and requires the resolved file to have the expected CSS extension. The specific HTTP endpoint used to place the crafted content is not identified by the CNA or upstream release note.
1.3.9
CVE4.9
NVDPending
Aug 26, 2024 CVE-2024-43299
SpeedyCache: Cross-site request forgery
SpeedyCache is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD5.4
Jan 11, 2024 CVE-2023-6598
SpeedyCache: A security weakness
SpeedyCache is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Dec 07, 2023 CVE-2023-49746
SpeedyCache – Cache, Optimization, Performance: Server-side request forgery
SpeedyCache – Cache, Optimization, Performance is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE4.9
NVD4.3