Junglewise Threat Intelligence

CVE-2026-15889: Aruba HiSpeed Cache stored cross-site scripting in post content

CVE-2026-15889 · Severity: medium · CVSS 6.4 · Published 2026-09-10

Executive brief

The Aruba HiSpeed Cache plugin for WordPress allows authenticated users with Contributor-level access to inject malicious scripts into post content. When published, these scripts execute in the browsers of all site visitors viewing that page, potentially stealing credentials, hijacking sessions, or defacing content. This affects websites running the plugin through version 3.0.14.

Technical details

The vulnerability is a Stored Cross-Site Scripting (XSS) flaw caused by insufficient input sanitization and output escaping of user-supplied post content within the HiSpeed Cache plugin. An authenticated attacker with Contributor-level access or higher can inject arbitrary JavaScript payloads into posts, which are stored in the database and executed in the browsers of all users viewing those pages. The attack requires authentication but no special privileges beyond the standard Contributor role. No patch availability is mentioned in the advisory.

Affected products

  • Aruba HiSpeed Cache up to and including 3.0.14

Timeline

  • 2026-09-10: disclosed

References