Impact
The Aruba HiSpeed Cache plugin for WordPress contains a stored cross‑site scripting flaw that allows authenticated users with Contributor level or higher to inject arbitrary JavaScript into post content. When modified content is viewed by other users, the malicious script executes in their browsers. This could be leveraged to perform session hijacking, credential theft, or defacement of the site.
Affected Systems
Any WordPress installation running the Aruba HiSpeed Cache plugin up to and including version 3.0.14 is affected. The vulnerability applies to all versions of the plugin where content is not properly sanitized before being stored and output. Users must verify the plugin version they are running and ensure it is patched.
Risk and Exploitability
The CVSS v3 base score is 6.4, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires authentication and at least Contributor privileges, so the attack vector is fairly limited but still useful for a malicious insider or compromised account. Once the attacker injects the payload, it runs with the victim's browser context, giving the attacker the ability to steal credentials or execute further malicious actions.
OpenCVE Enrichment