CVE-2025-67913
9.8Aruba.it · Aruba HiSpeed Cache
The Aruba HiSpeed Cache WordPress plugin contains a missing authorization vulnerability that allows unauthenticated users to access restricted functions.
Executive summary
A missing authorization vulnerability in the Aruba HiSpeed Cache WordPress plugin allows unauthenticated attackers to perform restricted actions within the plugin.
Vulnerability
This is a missing authorization vulnerability that fails to properly constrain functionality via Access Control Lists (ACLs). This allows an unauthenticated user to interact with sensitive plugin functions that should be reserved for administrators.
Business impact
Although the CVSS score is 9.8, the vector indicates limited impact on Confidentiality, Integrity, and Availability. However, the lack of authorization controls could allow an attacker to disrupt caching services, leading to performance degradation or potential denial of service for the website.
Remediation
Immediate Action: Update the Aruba HiSpeed Cache plugin to version 3.0.3 or higher.
Proactive Monitoring: Monitor server performance and cache status logs for unexpected behavior or unauthorized attempts to trigger cache management functions.
Compensating Controls: Implement a WAF to filter requests and prevent unauthorized access to plugin-specific configuration endpoints.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
All users of the Aruba HiSpeed Cache plugin must update to version 3.0.3 immediately. Failure to address this missing authorization vulnerability could allow attackers to manipulate caching behavior, potentially impacting site availability and performance.