Cross-Site Request Forgery in Aruba HiSpeed Cache Plugin for WordPress
CVE-2026-1924
4.3MEDIUM
What is CVE-2026-1924?
The Aruba HiSpeed Cache plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF) in all versions up to and including 3.0.4. This vulnerability arises from inadequate nonce verification in the ahsc_ajax_reset_options() function, enabling unauthorized attackers to exploit the flaw. By executing a forged request, an attacker could potentially reset the plugin's settings to their defaults, provided they can deceive a site administrator into triggering the malicious action, such as by clicking a compromised link.
Affected Version(s)
Aruba HiSpeed Cache 0 <= 3.0.4