CVE · Medium

CVE-2026-5114 — SpeedyCache – Cache, Optimization, Performance [speedycache] < 1.3.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-5114 SpeedyCache – Cache, Optimization, Performance [speedycache] < 1.3.9 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 4.9 < 1.3.9 1.3.9 2024-08-16

CVE-2026-5114

The SpeedyCache plugin for WordPress has a vulnerability that allows attackers with Administrator-level access to read sensitive files on the server. This occurs because the plugin doesn't properly validate file paths when resolving CSS files, allowing attackers to inject malicious links that can access files like wp-config.php and others. The plugin's caching mechanism then writes the contents of these files to publicly accessible cache files, effectively exposing sensitive information.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.