Aruba HiSpeed Cache
cpe:2.3:a:aruba:aruba_hispeed_cache:*:*:*:*:wordpress:*:*
- < 3.0.5
A cross-site request forgery (CSRF) vulnerability has been identified in the Aruba HiSpeed Cache WordPress plugin, affecting versions prior to 3.0.5. The vulnerability arises because the plugin's AJAX handlers for resetting options, debugging status, and cache purging do not properly validate WordPress nonces for state-changing requests. This oversight allows an attacker to trick a logged-in administrator into executing unauthorized actions, such as resetting plugin settings, altering the WP_DEBUG configuration, or changing cache purging behaviors, all without the administrator's knowledge.
Exploitation of this vulnerability could lead to unauthorized changes in plugin settings, WordPress debugging configurations, or cache management behaviors, potentially disrupting website performance or functionality.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.