HomeSecurityLiteSpeed ​​cPanel Plugin: Critical vulnerability actively exploited

LiteSpeed ​​cPanel Plugin: Critical vulnerability actively exploited

A critical security vulnerability affecting the LiteSpeed ​​User-End cPanel Pluginis currently being actively exploited. The vulnerability is tracked as CVE-2026-48172 and has a maximum CVSS score of 10.

LiteSpeed ​​cPanel Plugin vulnerability

The vulnerability is related to incorrect privilege assignment, which could be exploited by an attacker to execute arbitrary scripts with elevated privileges. Any cPanel user (or an attacker with access to an account) can exploit the lsws.redisAble function to execute scripts as root.

See also: WordPress: New serious vulnerability in LiteSpeed ​​Cache plugin

LiteSpeed ​​cPanel Plugin: Which versions are affected and fix

– LiteSpeed ​​User-End cPanel Plugin versions 2.3 to 2.4.4.
– Initial fix is ​​in 2.4.5.
– After additional security review, it is recommended to upgrade to LiteSpeed ​​WHM Plugin 5.3.1.0 which includes cPanel plugin v2.4.7 or later.

Why the vulnerability is so dangerous especially for shared hosting

In a shared hosting environment, a "simple" cPanel user corresponds to a client/tenant. If a vulnerability allows a jump from this level to root on the underlying server, then it could theoretically lead to:

– full control of the host,
– access to other customers' files/databases,
– installation of backdoors or webshells,
– ransomware on an entire node.

See also: Critical authentication vulnerability in cPanel – Update now

LiteSpeed ​​cPanel Plugin: Critical vulnerability actively exploited

How to quickly check for traces (IoC) in logs

The available instructions include a handy grep that searches for calls of the suspicious function in the cPanel logs:

grep -rE “cpanel_jsonapi_func=redisAble” /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null

– If it returns no result, it does not appear to be an exploit attempt with this pattern.
– If it returns lines, assume that there was at least probing (and potentially exploitation). Record timestamps/users/IPs and initiate incident response.

What to do now (mitigation)

1) Upgrade: target LiteSpeed ​​WHM Plugin 5.3.1.0 (bundled cPanel plugin 2.4.7+).
2) If you can't patch immediately: remove the user-end plugin (reduce attack surface). An example command has been published:
/usr/local/lsws/admin/misc/lscmctl cpanelplugin –uninstall
3) After patch/uninstall, check for:
– new users with sudo/root, changes to SSH authorized_keys,
– cron persistence,
– changes to file ownership/permissions,
– unknown binaries/processes,
– webshells in account directories.

See also: LiteSpeed ​​Cache WordPress: New vulnerability allows XSS attacks

LiteSpeed ​​cPanel Plugin: Critical vulnerability actively exploited

What does it mean for Greece / businesses / admins / users

– In Greece there are a large number of corporate sites/e-shops on shared hosting. For hosting providers and MSPs, the incident is “high priority” because a compromised cPanel account can become a complete server breach.
– For businesses: if you are hosted on a third-party provider, ask immediately if the plugin has been upgraded/removed and if logs have been checked.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS