{"id":"CVE-2026-5114","summary":"SpeedyCache \u003c= 1.3.8 - Authenticated (Administrator+) Arbitrary File Read","details":"The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.3.8. This is due to a mismatch between CSS URL validation (which allows query strings like `.css?...`) and path resolution (which strips query strings), combined with no validation that the resolved file is actually a CSS file. This makes it possible for authenticated attackers, with Administrator-level access and above, to read arbitrary files from the server (including `wp-config.php` and `/etc/passwd`) by injecting crafted `\u003clink\u003e` tags into page content, with the file contents written to publicly accessible cache files.","modified":"2026-10-06T02:39:08.777138837Z","published":"2026-07-28T18:35:52.121Z","database_specific":{"unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"last_affected":"1.3.8"}]}],"cna_assigner":"Wordfence","cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5114.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5114.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5114"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/speedycache/tags/1.3.7/main/css.php#L137"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/speedycache/tags/1.3.7/main/util.php#L75"},{"type":"WEB","url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cfefcc38-764d-4dd9-b098-cdcad475d634?source=cve"}],"affected":[{"package":{"name":"speedycache","ecosystem":"WordPress:Plugin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.3.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-5114.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"}]}