
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-11725 is a Missing Authorization vulnerability in the Aruba HiSpeed Cache plugin for WordPress that allows unauthenticated attackers to modify plugin configuration settings, enable or disable features, and toggle WordPress cron jobs or debug mode. All versions up to and including 3.0.2 are affected. The vulnerability was published on February 19, 2026, with a CVSS v3.1 base score of 6.5 (Medium) (Red Hat CVE, Wordfence).
The root cause is CWE-862 (Missing Authorization): multiple functions within the Aruba HiSpeed Cache plugin fail to perform capability checks before executing privileged operations (Red Hat CVE). Because no authentication or role verification is enforced, any unauthenticated remote attacker can send crafted HTTP requests to the affected plugin endpoints to alter caching configuration, toggle debug mode, or manipulate WordPress cron job scheduling. The attack vector is network-based, requires no privileges or user interaction, and has low attack complexity.
Successful exploitation allows unauthenticated attackers to modify the plugin's configuration settings, potentially disrupting caching behavior and site performance, enabling debug mode (which may expose sensitive application data), and manipulating WordPress cron jobs to interfere with scheduled site operations. The CVSS assessment reflects low confidentiality and low integrity impact with no direct availability impact, though enabling debug mode could inadvertently expose sensitive server-side information to further attacks (Red Hat CVE, Sucuri Blog).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-11725. The EPSS score is approximately 0.036%, indicating a low probability of exploitation in the near term (Red Hat CVE). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified.
admin-ajax.php endpoint (or equivalent REST API route) with the appropriate action parameter targeting one of the unprotected plugin functions — no authentication cookies or nonces are required.wp-admin/admin-ajax.php with action parameters associated with the Aruba HiSpeed Cache plugin from unknown or external IP addresses.hispeedcache settings.WP_DEBUG) or unexpected changes to cron job schedules observable via site behavior or wp-cron.php execution logs.WordPress site administrators should update the Aruba HiSpeed Cache plugin to a version beyond 3.0.2 that includes proper capability checks on all sensitive functions (Wordfence, Sucuri Blog). If no patched version is yet available, consider temporarily deactivating the plugin until a fix is released. Additionally, deploying a Web Application Firewall (WAF) such as Wordfence or Sucuri can help block unauthorized requests to plugin endpoints as a compensating control.
Wordfence included CVE-2025-11725 in its weekly WordPress vulnerability report for February 16–22, 2026, highlighting it as part of a broader set of WordPress plugin authorization issues (Wordfence). Sucuri also referenced the vulnerability in its February 2026 vulnerability patch roundup, recommending prompt updates for affected WordPress installations (Sucuri Blog). No significant social media controversy or vendor dispute has been noted.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."