logo

Hackers are exploiting critical bug in LiteSpeed Cache plugin

ID: 6d87866b-a45f-5762-90f6-b384b3f6aca4

STIX ID: report--6d87866b-a45f-5762-90f6-b384b3f6aca4

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-08-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The LiteSpeed Cache WordPress plugin has a critical unauthenticated privilege escalation vulnerability (CVE-2024-28000) that can be exploited by brute-forcing a weak hash to create admin accounts and fully take over sites. The flaw affects millions of installations, is being actively exploited (Wordfence reported ~48,500 blocked attacks in 24 hours), and site owners are urged to update to version 6.4.1 or uninstall the plugin immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.