logo

Litespeed Cache bug exposes millions of WordPress sites to takeover attacks

ID: 3e521345-0095-577f-9c51-27c20b5d5d79

STIX ID: report--3e521345-0095-577f-9c51-27c20b5d5d79

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-08-21

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

A critical unauthenticated privilege-escalation vulnerability (CVE-2024-28000) in the LiteSpeed Cache WordPress plugin (<= 6.3.0.1) allows attackers to brute-force a weak litespeed_hash value and create admin accounts to take over sites; a patch was released in versions 6.4/6.4.1 but many of the millions of installations appear unpatched and evidence of scanning and prior exploitation of related LiteSpeed flaws indicates active or imminent abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.