A critical vulnerability in the WordPress plugin LiteSpeed Cache could put millions of sites at risk , as attackers could take control of the websites by creating malicious administrator accounts.

LiteSpeed Cache is the most popular WordPress acceleration plugin, with over 5 million active installations and support for WooCommerce, bbPress, ClassicPress, and Yoast SEO.
The vulnerability is tracked as CVE-2024-28000 and allows for privilege escalation. It was discovered in the plugin's user simulation feature and is caused by a weak hash check in LiteSpeed Cache up to version 6.3.0.1.
See also: Vulnerability in GiveWP plugin puts thousands of sites at risk
Security researcher John Blackbourn reported the vulnerability to Patchstack's bug bounty program . The LiteSpeed team released a fix with version 6.4 of LiteSpeed Cache on August 13.
Successful exploitation allows any unauthenticated visitor to gain administrator-level access. This means an attacker could take complete control of a site running a vulnerable version of LiteSpeed Cache. They could install malicious plugins, change critical settings, redirect traffic to malicious websites, distribute malware to visitors, and steal credentials.
“We were able to determine that a attack brute force can gain access to the website, as any given user ID, within a few hours to a week,” Patchstack security researcher Rafie Muhammad explained on Wednesday.
See also: Modern Events Calendar – WordPress: Hackers target vulnerability
“The only requirement is to know the ID of an Administrator-level user and place it in the litespeed_role cookie. The difficulty of identifying such a user depends entirely on the target website“.
Despite the release of the update, download statistics show that the updated plugin has been downloaded just over 2.5 million times, likely leaving more than half of the websites using it exposed to attacks.
“We strongly advise users to update their websites with the latest LiteSpeed Cache update, version 6.4.1, as soon as possible. We have no doubt that this vulnerability will be exploited very soon,” warned Chloe Chamberland of Wordfence.
See also: New Caesar Cipher Skimmer Targets WordPress, Magento, and OpenCart Sites
Importance of WordPress protection
Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.

Additionally, an unsecured WordPress site can undermine the trust and credibility you’ve built with customers your. If their data is compromised, they’re more likely to sue you and switch to other companies.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Securing your website is also important for maintaining the consistency and credibility of content your. If a hacker breaks into your WordPress site and corrupts the content, it can give the impression that you don't care enough about your website.
In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining your customers ’ trust , preserving your company’s reputation, and staying on top of the competition.
Source: www.bleepingcomputer.com
