Junglewise Threat Intelligence

CVE-2026-54834: fpuenteonline Object Cache 4 everyone sensitive data exposure

CVE-2026-54834 · Severity: high · CVSS 7.5 · Published 2026-06-26

Executive brief

Object Cache 4 everyone is a WordPress plugin designed to improve website performance by caching data. A security flaw in versions 2.3.2 and earlier allows unauthenticated individuals to access sensitive information that should be private. This exposure could lead to further attacks or the compromise of user data and site configurations.

Technical details

The Object Cache 4 everyone plugin for WordPress (versions up to 2.3.2) is vulnerable to sensitive data exposure due to improper restriction of information sent to users (CWE-201). An unauthenticated remote attacker can exploit this vulnerability to view sensitive data that is normally restricted to authorized users. The vulnerability is categorized as high severity with a CVSS score of 7.5, as it requires no privileges or user interaction. A fix is available in version 2.3.3.

Affected products

  • fpuenteonline Object Cache 4 everyone <= 2.3.2

Timeline

  • 2026-04-30: disclosed: Reported by dodoh4t to Patchstack
  • 2026-06-17: advisory: Patchstack published advisory
  • 2026-06-26: advisory: NVD published CVE-2026-54834
  • 2026-06-26: patched: Version 2.3.3 released to address the issue

References