Executive brief
Object Cache 4 everyone is a WordPress plugin designed to improve website performance by caching data. A security flaw in versions 2.3.2 and earlier allows unauthenticated individuals to access sensitive information that should be private. This exposure could lead to further attacks or the compromise of user data and site configurations.
Technical details
The Object Cache 4 everyone plugin for WordPress (versions up to 2.3.2) is vulnerable to sensitive data exposure due to improper restriction of information sent to users (CWE-201). An unauthenticated remote attacker can exploit this vulnerability to view sensitive data that is normally restricted to authorized users. The vulnerability is categorized as high severity with a CVSS score of 7.5, as it requires no privileges or user interaction. A fix is available in version 2.3.3.
Affected products
- fpuenteonline Object Cache 4 everyone <= 2.3.2
Timeline
- 2026-04-30: disclosed: Reported by dodoh4t to Patchstack
- 2026-06-17: advisory: Patchstack published advisory
- 2026-06-26: advisory: NVD published CVE-2026-54834
- 2026-06-26: patched: Version 2.3.3 released to address the issue