Another critical vulnerability was discovered in LiteSpeed Cache, putting over 6 million WordPress websites.
LiteSpeed Cache is a caching plugin that helps speed up users' browsing. The vulnerability is tracked as CVE-2024-44000 and was discovered by Rafie Muhammad of Patchstack on August 22, 2024. The vulnerability could allow attackers to take control of vulnerable sites. A fix was made available the day before yesterday with the release of LiteSpeed Cache version 6.5.0.1.
See also: LiteSpeed Cache vulnerability puts millions of WordPress sites at risk
The vulnerability is linked to the debug logging feature , which logs all HTTP response headers to a file, including the “Set-Cookie” header, when enabled.

These headers contain session cookies that are used to authenticate users . As a result, if someone steals them, they can impersonate an administrator and take full control of the site.
To exploit the vulnerability, an attacker must have access to the debug log file at ‘/wp-content/debug.log.’ When file access restrictions (such as .htaccess rules) are not in place , access can be gained simply by entering the correct URL.
The attacker will only be able to steal the session cookies of users who logged into the site while the debug feature was active. However, login past events could also be affected if the logs are kept indefinitely
See also: Modern Events Calendar – WordPress: Hackers target vulnerability
LiteSpeed Technologies addressed the vulnerability in LiteSpeed Cache by moving the debug log to a dedicated folder ('/wp-content/litespeed/debug/'), randomizing log file names, removing the cookie logging option, and adding an index file for additional protection.
LiteSpeed Cache users are advised to clear all 'debug.log' files from their servers to delete valid session cookies.
It is also recommended to define a .htaccess rule to prevent direct access to log files.
WordPress.org noted that just over 375,000 users downloaded LiteSpeed Cache when version 6.5.0.1 was released, so the number of WordPress sites that remain vulnerable to the vulnerability may be over 5.6 million.

Importance of WordPress protection
Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.
See also: Slider Revolution: Two vulnerabilities found in WordPress plugin
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Additionally, an unsecured WordPress site can undermine the trust and credibility you’ve built with customers your. If their data is compromised, they’re more likely to sue you and switch to other companies.
Securing your website is also important for maintaining the consistency and credibility of content your. If a hacker breaks into your WordPress site and corrupts the content, it can give the impression that you don't care enough about your website.
In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining your customers ’ trust , preserving your company’s reputation, and staying on top of the competition.
Source: www.bleepingcomputer.com
