Hackers are exploiting an old vulnerable version of the LiteSpeed Cache plugin and creating administrator users to gain control of WordPress sites.

LiteSpeed Cache (LS Cache) is a caching plugin used on over five million WordPress sites. It helps speed up page loading, improve the site visitor experience, and boost Google Search rankings .
See also: Wpeeper: Uses Compromised WordPress Sites to Hide C2 Servers
Automattic's security team, WPScan, noticed in April that cybercriminals were looking for and compromising WordPress sites running versions of the LiteSpeed Cache plugin prior to 5.7.0.1. These versions are vulnerable to a serious vulnerability tracked as CVE-2023-40000. From one IP address, 94[.]102[.]51[.]144, there were more than 1.2 million probing requests, while scanning for vulnerable sites.
WPScan reports that the attacks use malicious JavaScript code that is injected into critical WordPress files or the database ,creating administrator users with the name “wpsupp-user” or “wp-configuser”. Additionally, on an infected site, the string “eval(atob(Strings.fromCharCode” may appear in the “litespeed.admin_display.messages” option in the database.
Fortunately, several users of the WordPress plugin LiteSpeed Cache have implemented more recent versions that are not affected by the vulnerability , but a significant number are still running a vulnerable version.
See also: WP Automatic WordPress plugin: Hackers exploit critical vulnerability
Creating administrator accounts on WordPress sites allows attackers to have complete control over the site, which means they can modify content, install plugins, change settings, redirect traffic, distribute malware, steal user data, and more.
Therefore, it is recommended that WordPress site administrators update plugins (e.g. LiteSpeed Cache) to the latest version, remove or disable components that are not needed, and monitor the creation of new administrator accounts.
A complete cleanup of the site is mandatory in case of a confirmed breach.
Importance of WordPress protection
Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.

Additionally, an unsecured WordPress site can undermine the trust and credibility you’ve built with customers your. If their data is compromised, they’re more likely to sue you and switch to other companies.
See also: Forminator plugin: Critical vulnerability affects thousands of WordPress sites
Securing your website is also important for maintaining the consistency and reliability of content your. If a hacker compromises your WordPress site (e.g. through a vulnerability in the LiteSpeed Cache plugin) and corrupts the content, it can give the impression that you are not doing enough with your website.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining your customers ’ trust , preserving your company’s reputation, and staying on top of the competition.
Source: www.bleepingcomputer.com
