LiteSpeed Cache bug exposes 6 million WordPress sites to takeover attacks
ID: 5b6ff6e0-375a-5391-a962-7ba6a2c06ccb
STIX ID: report--5b6ff6e0-375a-5391-a962-7ba6a2c06ccb
Feed Name: Bleeping Computer
A critical unauthenticated account-takeover flaw (CVE-2024-44000) in the LiteSpeed Cache WordPress plugin was disclosed: the plugin's debug logging feature wrote HTTP response headers (including Set-Cookie) to /wp-content/debug.log, allowing attackers who can access that file to steal session cookies and impersonate admin users. LiteSpeed released v6.5.0.1 to move and harden logging, randomize filenames, and stop logging cookies; users are advised to purge debug.log files and restrict access. Given the plugin's wide deployment (millions of sites) and recent mass-exploitation activity against related LiteSpeed flaws, unpatched installations pose a significant takeover risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
