PT-2026-21555 · WordPress · Aruba Hispeed Cache
Rahul Karne
+1
·
Publicado
2026-02-23
·
Atualizado
2026-02-24
·
CVE-2026-23694
CVSS v4.0
5.1
Média
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Aruba HiSpeed Cache WordPress plugin versions prior to 3.0.5
Description
The Aruba HiSpeed Cache WordPress plugin is susceptible to a cross-site request forgery (CSRF) issue impacting several administrative AJAX actions. Specifically, the
ahsc reset options, ahsc debug status, and ahsc enable purge handlers authenticate and check user capabilities but fail to validate a WordPress nonce for requests that alter the system's state. An attacker could potentially trick a logged-in administrator into visiting a malicious webpage, causing the submission of forged requests to the admin-ajax.php endpoint. This could lead to unauthorized changes, such as resetting plugin settings, modifying the WordPress WP DEBUG configuration, or altering cache purging behavior. The vulnerable parameters are not explicitly mentioned.Recommendations
Update Aruba HiSpeed Cache WordPress plugin to version 3.0.5 or later.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Aruba Hispeed Cache