CVE-2025-67913

9.8

Aruba.it · Aruba HiSpeed Cache

The Aruba HiSpeed Cache WordPress plugin contains a missing authorization vulnerability that allows unauthenticated users to access restricted functions.

Executive summary

A missing authorization vulnerability in the Aruba HiSpeed Cache WordPress plugin allows unauthenticated attackers to perform restricted actions within the plugin.

Vulnerability

This is a missing authorization vulnerability that fails to properly constrain functionality via Access Control Lists (ACLs). This allows an unauthenticated user to interact with sensitive plugin functions that should be reserved for administrators.

Business impact

Although the CVSS score is 9.8, the vector indicates limited impact on Confidentiality, Integrity, and Availability. However, the lack of authorization controls could allow an attacker to disrupt caching services, leading to performance degradation or potential denial of service for the website.

Remediation

Immediate Action: Update the Aruba HiSpeed Cache plugin to version 3.0.3 or higher.

Proactive Monitoring: Monitor server performance and cache status logs for unexpected behavior or unauthorized attempts to trigger cache management functions.

Compensating Controls: Implement a WAF to filter requests and prevent unauthorized access to plugin-specific configuration endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

All users of the Aruba HiSpeed Cache plugin must update to version 3.0.3 immediately. Failure to address this missing authorization vulnerability could allow attackers to manipulate caching behavior, potentially impacting site availability and performance.