PT-2026-21555 · WordPress · Aruba Hispeed Cache

Rahul Karne

+1

·

Publicado

2026-02-23

·

Atualizado

2026-02-24

·

CVE-2026-23694

CVSS v4.0

5.1

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Aruba HiSpeed Cache WordPress plugin versions prior to 3.0.5
Description The Aruba HiSpeed Cache WordPress plugin is susceptible to a cross-site request forgery (CSRF) issue impacting several administrative AJAX actions. Specifically, the ahsc reset options, ahsc debug status, and ahsc enable purge handlers authenticate and check user capabilities but fail to validate a WordPress nonce for requests that alter the system's state. An attacker could potentially trick a logged-in administrator into visiting a malicious webpage, causing the submission of forged requests to the admin-ajax.php endpoint. This could lead to unauthorized changes, such as resetting plugin settings, modifying the WordPress WP DEBUG configuration, or altering cache purging behavior. The vulnerable parameters are not explicitly mentioned.
Recommendations Update Aruba HiSpeed Cache WordPress plugin to version 3.0.5 or later.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-23694

Produtos afetados

Aruba Hispeed Cache