SpeedyCache – Cache, Optimization, Performance
SpeedyCache – Cache, Optimization, Performance is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 5.4.
speedycacheCVE-2026-5114: SpeedyCache administrator path traversal exposes server files through public cache files
SpeedyCache through 1.3.8 is vulnerable to arbitrary file read when an Administrator injects a crafted stylesheet link into page content. CSS::combine() accepts a URL when its full value contains a .css suffix, including a .css marker placed in the query portion. Util::url_to_path() then removes everything from the first question mark onward without confirming the resolved path remains inside WordPress or points to a CSS file. The resulting path is passed to file_get_contents(), and its contents are written into a publicly accessible combined-CSS cache file. This permits disclosure of files such as wp-config.php and /etc/passwd. Version 1.3.9 resolves and confines the path to the WordPress installation and requires the resolved file to have the expected CSS extension. The specific HTTP endpoint used to place the crafted content is not identified by the CNA or upstream release note.
| Safe version |
|
||
|---|---|---|---|
| Jul 28, 2026 |
CVE-2026-5114
SpeedyCache administrator path traversal exposes server files through public cache files
SpeedyCache through 1.3.8 is vulnerable to arbitrary file read when an Administrator injects a crafted stylesheet link into page content. CSS::combine() accepts a URL when its full value contains a .css suffix, including a .css marker placed in the query portion. Util::url_to_path() then removes everything from the first question mark onward without confirming the resolved path remains inside WordPress or points to a CSS file. The resulting path is passed to file_get_contents(), and its contents are written into a publicly accessible combined-CSS cache file. This permits disclosure of files such as wp-config.php and /etc/passwd. Version 1.3.9 resolves and confines the path to the WordPress installation and requires the resolved file to have the expected CSS extension. The specific HTTP endpoint used to place the crafted content is not identified by the CNA or upstream release note.
|
1.3.9 |
CVE4.9
NVDPending
|
| Aug 26, 2024 |
CVE-2024-43299
SpeedyCache: Cross-site request forgery
SpeedyCache is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Jan 11, 2024 |
CVE-2023-6598
SpeedyCache: A security weakness
SpeedyCache is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Dec 07, 2023 |
CVE-2023-49746
SpeedyCache – Cache, Optimization, Performance: Server-side request forgery
SpeedyCache – Cache, Optimization, Performance is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE4.9
NVD4.3
|