HomeSecurityWordPress: New serious vulnerability in LiteSpeed ​​Cache plugin

WordPress: New serious vulnerability in LiteSpeed ​​Cache plugin

A serious vulnerability in the LiteSpeed ​​Cache plugin puts millions of WordPress sites at risk, allowing unauthorized attackers to escalate privileges and perform malicious actions.

LiteSpeed ​​Cache plugin vulnerability WordPress

The vulnerability is tracked as CVE-2024-50550 (CVSS score: 8.1) and has been addressed in version 6.5.2 of the plugin.

“The plugin is vulnerable to a privilege escalation vulnerability, which allows any unauthenticated visitor to gain access and install malicious plugins,” said Patchstack security researcher Rafie Muhammad.

See also: WordPress sites hacked: Fake plugins promote info-stealer malware

LiteSpeed ​​Cache is a popular acceleration plugin for WordPress sites and is installed on over six million websites.

The vulnerability is located in a function named is_role_simulation and is similar to an older bug reported in August 2024 (CVE-2024-28000, CVSS score: 9.8).

It is caused by a weak security hash check , which could be brute-forced by an attacker, allowing the crawler feature to be abused to impersonate a logged-in user, including an administrator.

See also: LiteSpeed ​​Cache WordPress: New vulnerability allows XSS attacks

However, a successful exploit relies on the following plugin configuration –

Crawler -> General Settings -> Crawler: ON

Crawler -> General Settings -> Run Duration: 2500 – 4000

Crawler -> General Settings -> Interval Between Runs: 2500 – 4000

Crawler -> General Settings -> Server Load Limit: 0

Crawler -> Simulation Settings -> Role Simulation: 1 (user ID with administrator role)

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Crawler -> Summary -> Activate: Turn every row to OFF except Administrator

Updating the LiteSpeed ​​Cache pluginremoves the role simulation process and updates the hash generation using a random value generator.

CVE-2024-50550 is the third vulnerability to be disclosed in LiteSpeed ​​in the past two months. The other two bugs were CVE-2024-44000 (CVSS score: 7.5) and CVE-2024-47374 (CVSS score: 7.2).

WordPress: New serious vulnerability in LiteSpeed ​​Cache plugin

Importance of WordPress protection

Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.

Additionally, an unsecured WordPress site can undermine the trust and credibility you’ve built with customers your. If their data is compromised, they’re more likely to sue you and switch to other companies.

See also: Security vulnerabilities in Houzez WordPress Theme and Plugin

Securing your website is also important for maintaining the consistency and credibility of content your. If a hacker breaks into your WordPress site and corrupts the content, it can give the impression that you don't care enough about your website.

In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining your customers  ’ trust , preserving your company’s reputation, and staying on top of the competition.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS