Impact
The Aruba HiSpeed Cache plugin suffers from a missing authorization flaw that enables an attacker to bypass the plugin’s access control and invoke privileged operations beyond their intended role. This flaw aligns with the CWE-862 "Missing Authorization" weakness, leading to the potential compromise of site configuration, content, or administrative functions.
Affected Systems
WordPress installations running Aruba.it Dev Aruba HiSpeed Cache version 3.0.4 or earlier are affected. The vulnerability is present in any installation of the plugin where the default or custom access control settings have been incorrectly configured or left unchanged.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating a moderate impact. The EPSS score is lower than 1%, suggesting a low probability of exploitation in the wild; it is not listed in the CISA KEV catalog. However, if a public WordPress site deploys a vulnerable plugin version, attackers can remotely submit crafted requests to the plugin’s endpoints to elevate privileges and take full control of the site, especially if the plugin is exposed through a standard URL pattern.
OpenCVE Enrichment