plugin

Aruba Hispeed Cache Vulnerabilities

14 known security issues reported for the Aruba Hispeed Cache WordPress plugin. Most recent disclosed Apr 9, 2026.

7 medium

Running Aruba Hispeed Cache on your site? Check whether your installed version is affected.

Scan your site free

Aruba HiSpeed Cache <= 3.0.4 - Cross-Site Request Forgery to Plugin Settings Reset

medium

The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. This is due to missing nonce verification on the `ahsc_ajax_reset_options()` function. This makes it possible for unauthenticated attackers to reset all plugin settings to their default...

CVSS:
4.3
Affected:
up to 3.0.4
Fixed in:
3.0.5
Disclosed:
Apr 9, 2026

CVE-2026-1924 on NVD →

Aruba HiSpeed Cache [aruba-hispeed-cache] < 3.0.5

unknown

[en] Aruba HiSpeed Cache (aruba-hispeed-cache) WordPress plugin versions prior to 3.0.5 contain a cross-site request forgery (CSRF) vulnerability affecting multiple administrative AJAX actions. The handlers for ahsc_reset_options, ahsc_debug_status, and ahsc_enable_purge perform authentication and capability checks but...

Affected:
up to 3.0.5
Fixed in:
3.0.5
Disclosed:
Feb 23, 2026

CVE-2026-23694 on NVD →

Aruba HiSpeed Cache [aruba-hispeed-cache] < 3.0.3

unknown

[en] The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the multiple functions in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to modify plugin's configuration settings, enable or disable...

Affected:
up to 3.0.3
Fixed in:
3.0.3
Disclosed:
Feb 19, 2026

CVE-2025-11725 on NVD →

Aruba HiSpeed Cache [aruba-hispeed-cache] < 3.0.3

unknown

[en] The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the dbstatus parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

Affected:
up to 3.0.3
Fixed in:
3.0.3
Disclosed:
Feb 19, 2026

CVE-2025-11706 on NVD →

Aruba HiSpeed Cache [aruba-hispeed-cache] <= 3.0.4 (unfixed)

unknown

[en] Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aruba HiSpeed Cache: from n/a through <= 3.0.4.

Affected:
up to 3.0.4
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-23545 on NVD →

Aruba HiSpeed Cache <= 3.0.2 - Missing Authorization to Unauthenticated Plugin's Settings Modification

medium

The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the multiple functions in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to modify plugin's configuration settings, enable or disable feat...

CVSS:
6.5
Affected:
up to 3.0.2
Fixed in:
3.0.3
Disclosed:
Feb 18, 2026

CVE-2025-11725 on NVD →

Aruba HiSpeed Cache <= 3.0.2 - Reflected Cross-Site Scripting

medium

The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the dbstatus parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

CVSS:
6.1
Affected:
up to 3.0.2
Fixed in:
3.0.3
Disclosed:
Feb 18, 2026

CVE-2025-11706 on NVD →

Aruba HiSpeed Cache <= 3.0.4 - Missing Authorization

medium

The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.0.4
Fixed in:
3.0.5
Disclosed:
Feb 18, 2026

CVE-2026-23545 on NVD →

Aruba HiSpeed Cache [aruba-hispeed-cache] < 3.0.3

unknown

[en] Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Aruba HiSpeed Cache: from n/a through < 3.0.3.

Affected:
up to 3.0.3
Fixed in:
3.0.3
Disclosed:
Jan 8, 2026

CVE-2025-67913 on NVD →

Aruba HiSpeed Cache < 3.0.3 - Missing Authorization

medium

The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 3.0.3 (exclusive). This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.0.3
Fixed in:
3.0.3
Disclosed:
Jan 1, 2026

CVE-2025-67913 on NVD →

Aruba HiSpeed Cache [aruba-hispeed-cache] < 2.0.13

unknown

[en] Missing Authorization vulnerability in Aruba.It Aruba HiSpeed Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aruba HiSpeed Cache: from n/a through 2.0.12.

Affected:
up to 2.0.13
Fixed in:
2.0.13
Disclosed:
Nov 1, 2024

CVE-2024-43119 on NVD →

Aruba HiSpeed Cache <= 2.0.12 - Missing Authorization

medium

The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ahsc_tool_bar_purge() function in versions up to, and including, 2.0.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to purge cache.

CVSS:
4.3
Affected:
up to 2.0.12
Fixed in:
2.0.13
Disclosed:
Aug 7, 2024

CVE-2024-43119 on NVD →

Aruba HiSpeed Cache [aruba-hispeed-cache] < 2.0.7

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Aruba.It Aruba HiSpeed Cache.This issue affects Aruba HiSpeed Cache: from n/a through 2.0.6.

Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Dec 19, 2023

CVE-2023-44983 on NVD →

Aruba HiSpeed Cache <= 2.0.6 - Sensitive Information Exposure via Log File

medium

The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.6 via the plugin's log file. This makes it possible for unauthenticated attackers to extract sensitive data including debug and trace information.

CVSS:
5.3
Affected:
up to 2.0.6
Fixed in:
2.0.7
Disclosed:
Nov 28, 2023

CVE-2023-44983 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database