logo

Hackers Exploiting LiteSpeed Cache Bug to Gain Full Control of WordPress Sites

ID: 0030468d-62db-53db-85f9-a6f92f07e463

STIX ID: report--0030468d-62db-53db-85f9-a6f92f07e463

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-05-08

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

A high-severity stored XSS vulnerability (CVE-2023-40000, CVSS 8.3) in the LiteSpeed Cache WordPress plugin is being actively exploited to create rogue admin accounts (e.g., wpsupp-user, wp-configuser) and inject JavaScript hosted on domains such as dns.startservicefounds.com and api.startservicefounds.com; the flaw was patched in version 5.7.0.1 but many sites remain on vulnerable versions. Separately, the Mal.Metrica redirect scam abuses injected scripts and fake CAPTCHA prompts to redirect visitors to scammy or malicious sites, with approximately 17,449 sites noted as compromised; recommended mitigations include applying updates, auditing plugins/files, and removing suspicious content.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.