Aruba HiSpeed Cache <= 3.0.4 - Cross-Site Request Forgery to Plugin Settings Reset
medium
The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. This is due to missing nonce verification on the `ahsc_ajax_reset_options()` function. This makes it possible for unauthenticated attackers to reset all plugin settings to their default...
- CVSS:
- 4.3
- Affected:
- up to 3.0.4
- Fixed in:
- 3.0.5
- Disclosed:
- Apr 9, 2026
CVE-2026-1924 on NVD →
Aruba HiSpeed Cache [aruba-hispeed-cache] < 3.0.5
unknown
[en] Aruba HiSpeed Cache (aruba-hispeed-cache) WordPress plugin versions prior to 3.0.5 contain a cross-site request forgery (CSRF) vulnerability affecting multiple administrative AJAX actions. The handlers for ahsc_reset_options, ahsc_debug_status, and ahsc_enable_purge perform authentication and capability checks but...
- Affected:
- up to 3.0.5
- Fixed in:
- 3.0.5
- Disclosed:
- Feb 23, 2026
CVE-2026-23694 on NVD →
Aruba HiSpeed Cache [aruba-hispeed-cache] < 3.0.3
unknown
[en] The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the multiple functions in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to modify plugin's configuration settings, enable or disable...
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.3
- Disclosed:
- Feb 19, 2026
CVE-2025-11725 on NVD →
Aruba HiSpeed Cache [aruba-hispeed-cache] < 3.0.3
unknown
[en] The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the dbstatus parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.3
- Disclosed:
- Feb 19, 2026
CVE-2025-11706 on NVD →
Aruba HiSpeed Cache [aruba-hispeed-cache] <= 3.0.4 (unfixed)
unknown
[en] Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aruba HiSpeed Cache: from n/a through <= 3.0.4.
- Affected:
- up to 3.0.4
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-23545 on NVD →
Aruba HiSpeed Cache <= 3.0.2 - Missing Authorization to Unauthenticated Plugin's Settings Modification
medium
The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the multiple functions in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to modify plugin's configuration settings, enable or disable feat...
- CVSS:
- 6.5
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.3
- Disclosed:
- Feb 18, 2026
CVE-2025-11725 on NVD →
Aruba HiSpeed Cache <= 3.0.2 - Reflected Cross-Site Scripting
medium
The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the dbstatus parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- CVSS:
- 6.1
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.3
- Disclosed:
- Feb 18, 2026
CVE-2025-11706 on NVD →
Aruba HiSpeed Cache <= 3.0.4 - Missing Authorization
medium
The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.0.4
- Fixed in:
- 3.0.5
- Disclosed:
- Feb 18, 2026
CVE-2026-23545 on NVD →
Aruba HiSpeed Cache [aruba-hispeed-cache] < 3.0.3
unknown
[en] Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Aruba HiSpeed Cache: from n/a through < 3.0.3.
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.3
- Disclosed:
- Jan 8, 2026
CVE-2025-67913 on NVD →
Aruba HiSpeed Cache < 3.0.3 - Missing Authorization
medium
The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 3.0.3 (exclusive). This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.3
- Disclosed:
- Jan 1, 2026
CVE-2025-67913 on NVD →
Aruba HiSpeed Cache [aruba-hispeed-cache] < 2.0.13
unknown
[en] Missing Authorization vulnerability in Aruba.It Aruba HiSpeed Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aruba HiSpeed Cache: from n/a through 2.0.12.
- Affected:
- up to 2.0.13
- Fixed in:
- 2.0.13
- Disclosed:
- Nov 1, 2024
CVE-2024-43119 on NVD →
Aruba HiSpeed Cache <= 2.0.12 - Missing Authorization
medium
The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ahsc_tool_bar_purge() function in versions up to, and including, 2.0.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to purge cache.
- CVSS:
- 4.3
- Affected:
- up to 2.0.12
- Fixed in:
- 2.0.13
- Disclosed:
- Aug 7, 2024
CVE-2024-43119 on NVD →
Aruba HiSpeed Cache [aruba-hispeed-cache] < 2.0.7
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Aruba.It Aruba HiSpeed Cache.This issue affects Aruba HiSpeed Cache: from n/a through 2.0.6.
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Dec 19, 2023
CVE-2023-44983 on NVD →
Aruba HiSpeed Cache <= 2.0.6 - Sensitive Information Exposure via Log File
medium
The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.6 via the plugin's log file. This makes it possible for unauthenticated attackers to extract sensitive data including debug and trace information.
- CVSS:
- 5.3
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.7
- Disclosed:
- Nov 28, 2023
CVE-2023-44983 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database