Aruba HiSpeed Cache

Aruba HiSpeed Cache has 8 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 8 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.5 out of 10. 2026 was the busiest year with 6 disclosures.

The most common weakness is Missing Authorization, behind 4 of the records (50%). Other recurring categories include Cross-Site Scripting, Cross-Site Request Forgery (CSRF).

Every one of the 8 issues recorded for Aruba HiSpeed Cache has a vendor fix available, so running the current release closes all known holes.

5 independent researchers contributed these findings, most of them (2) reported by Legion Hunter. Aruba HiSpeed Cache is installed on roughly 100,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.4/ 10
Patch Coverage100%
Open

0

Fixed

8

Get automatic notifications for all Aruba HiSpeed Cache vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.5CVE-2025-11725

Aruba HiSpeed Cache <= 3.0.2 - Missing Authorization to Unauthenticated Plugin's Settings Modification

Read the full analysis

Vulnerability Records

8 records
Aruba HiSpeed Cache banner
Latestv3.0.15

Aruba HiSpeed Cache

Aruba.it Dev

Author

Aruba.it Dev

3.0(10)
60/100
Last Updated
2026-08-31 (13d ago)
Active Installs
100,000+
Downloads
1,217,024
Requires WP
6.2+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2022-03-14 (5y ago)

Aruba HiSpeed Cache is a plugin that interfaces directly with the HiSpeed Cache service for an Aruba hosting platform and automates its management in the WordPress dashboard, without having to access the website’s control panel. The plugin can only be used if your WordPress website is hosted on an Aruba hosting platform. The HiSpeed Cache service significantly reduces the TTFB (first Byte transfer time) and webpage loading times. When the service is active, using the plugin allows you to automatically (and/or manually) clear the cache whenever a page or post is modified, without needing to access the website’s control panel by clicking the dedicated link. Thanks to AI, HiSpeed Cache analyzes traffic on your pages to automatically preload the most requested content, improving your users’ browsing experience. In addition, it stores dynamic content in the server memory after the first load, making it available for subsequent requests in a significantly shorter time, thus making website navigation much faster. The plugin simply clears the cache whenever a page, post, or custom content type is modified. For more details and to find out whether the HiSpeed Cache service is active on your website please refer to our guide.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C