logo

LiteSpeed Cache bug exposes 6 million WordPress sites to takeover attacks

ID: 5b6ff6e0-375a-5391-a962-7ba6a2c06ccb

STIX ID: report--5b6ff6e0-375a-5391-a962-7ba6a2c06ccb

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-09-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical unauthenticated account-takeover flaw (CVE-2024-44000) in the LiteSpeed Cache WordPress plugin was disclosed: the plugin's debug logging feature wrote HTTP response headers (including Set-Cookie) to /wp-content/debug.log, allowing attackers who can access that file to steal session cookies and impersonate admin users. LiteSpeed released v6.5.0.1 to move and harden logging, randomize filenames, and stop logging cookies; users are advised to purge debug.log files and restrict access. Given the plugin's wide deployment (millions of sites) and recent mass-exploitation activity against related LiteSpeed flaws, unpatched installations pose a significant takeover risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.