Impact
The Aruba HiSpeed Cache WordPress plugin is vulnerable to reflected Cross‑Site Scripting (XSS) because the dbstatus parameter is not validated or escaped before being output. An unauthenticated attacker can embed arbitrary JavaScript in a crafted URL and, if a user follows the link, the script is executed in the victim’s browser. This could enable hijacking of user sessions, theft of cookies, or other client‑side attacks. The impact is on confidentiality and integrity of the user’s browser session.
Affected Systems
WordPress sites running the Aruba HiSpeed Cache plugin version 3.0.2 or older. The vulnerable code resides in all releases up to and including 3.0.2. The plugin is distributed by Aruba Dev under the arubadev vendor namespace.
Risk and Exploitability
The CVSS score of 6.1 rates this vulnerability as moderate. The EPSS score of less than 1% indicates a low likelihood of widespread exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the attack requires only a URL link and can be triggered by any user, the potential impact remains significant. The likely attack vector is a crafted HTTP request containing a malicious dbstatus value delivered via a phishing or social‑engineering link. If a user clicks such a link, the embedded script runs with the privileges of the visitor’s browser.
OpenCVE Enrichment