A serious vulnerability in the LiteSpeed Cache plugin puts millions of WordPress sites at risk, allowing unauthorized attackers to escalate privileges and perform malicious actions.

The vulnerability is tracked as CVE-2024-50550 (CVSS score: 8.1) and has been addressed in version 6.5.2 of the plugin.
“The plugin is vulnerable to a privilege escalation vulnerability, which allows any unauthenticated visitor to gain access and install malicious plugins,” said Patchstack security researcher Rafie Muhammad.
See also: WordPress sites hacked: Fake plugins promote info-stealer malware
LiteSpeed Cache is a popular acceleration plugin for WordPress sites and is installed on over six million websites.
The vulnerability is located in a function named is_role_simulation and is similar to an older bug reported in August 2024 (CVE-2024-28000, CVSS score: 9.8).
It is caused by a weak security hash check , which could be brute-forced by an attacker, allowing the crawler feature to be abused to impersonate a logged-in user, including an administrator.
See also: LiteSpeed Cache WordPress: New vulnerability allows XSS attacks
However, a successful exploit relies on the following plugin configuration –
Crawler -> General Settings -> Crawler: ON
Crawler -> General Settings -> Run Duration: 2500 – 4000
Crawler -> General Settings -> Interval Between Runs: 2500 – 4000
Crawler -> General Settings -> Server Load Limit: 0
Crawler -> Simulation Settings -> Role Simulation: 1 (user ID with administrator role)
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Crawler -> Summary -> Activate: Turn every row to OFF except Administrator
Updating the LiteSpeed Cache pluginremoves the role simulation process and updates the hash generation using a random value generator.
CVE-2024-50550 is the third vulnerability to be disclosed in LiteSpeed in the past two months. The other two bugs were CVE-2024-44000 (CVSS score: 7.5) and CVE-2024-47374 (CVSS score: 7.2).

Importance of WordPress protection
Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.
Additionally, an unsecured WordPress site can undermine the trust and credibility you’ve built with customers your. If their data is compromised, they’re more likely to sue you and switch to other companies.
See also: Security vulnerabilities in Houzez WordPress Theme and Plugin
Securing your website is also important for maintaining the consistency and credibility of content your. If a hacker breaks into your WordPress site and corrupts the content, it can give the impression that you don't care enough about your website.
In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining your customers ’ trust , preserving your company’s reputation, and staying on top of the competition.
Source: thehackernews.com
