CVE-2026-1924: Aruba HiSpeed Cache <= 3.0.4 - Cross-Site Request Forgery to Plugin Settings Reset
The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. This is due to missing nonce verification on the ahscajaxresetoptions() function. This makes it possible for unauthenticated attackers to reset all plugin settings to their default values via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1924?
CVE-2026-1924 is classified as a medium severity vulnerability due to its impact on user data and security.
How do I fix CVE-2026-1924?
To mitigate CVE-2026-1924, update the Aruba HiSpeed Cache plugin to version 3.0.5 or later.
What type of vulnerability is CVE-2026-1924?
CVE-2026-1924 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Aruba HiSpeed Cache plugin.
Which versions of Aruba HiSpeed Cache are affected by CVE-2026-1924?
CVE-2026-1924 affects all versions of Aruba HiSpeed Cache up to and including version 3.0.4.
What are the consequences of exploiting CVE-2026-1924?
Exploiting CVE-2026-1924 could allow an attacker to reset plugin settings without the user's consent.