CVE-2026-1924: Aruba HiSpeed Cache <= 3.0.4 - Cross-Site Request Forgery to Plugin Settings Reset
The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. This is due to missing nonce verification on the `ahsc_ajax_reset_options()` function. This makes it possible for unauthenticated attackers to reset all plugin settings to their default values via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1924?
CVE-2026-1924 is classified as a medium severity vulnerability due to its impact on user data and security.
How do I fix CVE-2026-1924?
To mitigate CVE-2026-1924, update the Aruba HiSpeed Cache plugin to version 3.0.5 or later.
What type of vulnerability is CVE-2026-1924?
CVE-2026-1924 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Aruba HiSpeed Cache plugin.
Which versions of Aruba HiSpeed Cache are affected by CVE-2026-1924?
CVE-2026-1924 affects all versions of Aruba HiSpeed Cache up to and including version 3.0.4.
What are the consequences of exploiting CVE-2026-1924?
Exploiting CVE-2026-1924 could allow an attacker to reset plugin settings without the user's consent.