Litespeed Cache bug exposes millions of WordPress sites to takeover attacks

Share:

A critical vulnerability in the LiteSpeed Cache WordPress plugin can let attackers take over millions of websites after creating rogue admin accounts.

LiteSpeed Cache is open-source and the most popular WordPress site acceleration plugin, with over 5 million active installations and support for WooCommerce, bbPress, ClassicPress, and Yoast SEO.

The unauthenticated privilege escalation vulnerability (CVE-2024-28000) was found in the plugin’s user simulation feature and is caused by a weak hash check in LiteSpeed Cache up to and including version 6.3.0.1.

Security researcher John Blackbourn submitted the flaw to Patchstack’s bug bounty program on August 1. The LiteSpeed team developed a patch and shipped it with LiteSpeed Cache version 6.4, released on August 13.

Successful exploitation enables any unauthenticated visitors to gain administrator-level access, which can be used to completely take over websites running vulnerable LiteSpeed Cache versions by installing malicious plugins, changing critical settings, redirecting traffic to malicious websites, distributing malware to visitors, or stealing user data.

“We were able to determine that a brute force attack that iterates all 1 million known possible values for the security hash and passes them in the litespeed_hash cookie — even running at a relatively low 3 requests per second — is able to gain access to the site as any given user ID within between a few hours and a week,” explained Patchstack security researcher Rafie Muhammad on Wednesday.

“The only prerequisite is knowing the ID of an Administrator-level user and passing it in the litespeed_role cookie. The difficulty of determining such a user depends entirely on the target site and will succeed with a user ID 1 in many cases.”

While the development team released versions that address this critical security vulnerability last Tuesday, download statistics from WordPress’ official plugin repository show that the plugin has only been downloaded just over 2.5 million times, likely leaving more than half of all websites using it exposed to incoming attacks.

Earlier this year, attackers exploited a LiteSpeed Cache unauthenticated cross-site scripting flaw (CVE-2023-40000) to create rogue administrator users and gain control of vulnerable websites. In May, Automattic’s security team, WPScan, warned that threat actors started scanning for targets in April after seeing over 1.2 million probes from just one malicious IP address.

“We strongly advise users to update their sites with the latest patched version of Litespeed Cache, version 6.4.1 at the time of this writing, as soon as possible. We have no doubts that this vulnerability will be actively exploited very soon,” Wordfence threat intel lead Chloe Chamberland also warned today.

In June, the Wordfence Threat Intelligence team also reported that a threat actor backdoored at least five plugins on WordPress.org and added malicious PHP scripts to create accounts with admin privileges on websites running them.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:35 pm, Jul 3, 2025
weather icon 24°C
L: 23° | H: 25°
few clouds
Humidity: 34 %
Pressure: 1027 mb
Wind: 6 mph SSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 14%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:49 am
Sunset: 9:20 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
23° | 25°°C 0 mm 0% 11 mph 36 % 1027 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
13° | 27°°C 0 mm 0% 12 mph 58 % 1029 mb 0 mm/h
Sat Jul 05 10:00 pm
weather icon
15° | 18°°C 1 mm 100% 11 mph 95 % 1021 mb 0 mm/h
Sun Jul 06 10:00 pm
weather icon
15° | 18°°C 0.87 mm 87% 11 mph 92 % 1009 mb 0 mm/h
Mon Jul 07 10:00 pm
weather icon
13° | 18°°C 1 mm 100% 11 mph 76 % 1013 mb 0 mm/h
Today 4:00 pm
weather icon
24° | 24°°C 0 mm 0% 3 mph 34 % 1026 mb 0 mm/h
Today 7:00 pm
weather icon
23° | 23°°C 0 mm 0% 11 mph 32 % 1026 mb 0 mm/h
Today 10:00 pm
weather icon
19° | 20°°C 0 mm 0% 9 mph 36 % 1027 mb 0 mm/h
Tomorrow 1:00 am
weather icon
16° | 16°°C 0 mm 0% 7 mph 45 % 1029 mb 0 mm/h
Tomorrow 4:00 am
weather icon
13° | 13°°C 0 mm 0% 5 mph 56 % 1028 mb 0 mm/h
Tomorrow 7:00 am
weather icon
15° | 15°°C 0 mm 0% 4 mph 58 % 1028 mb 0 mm/h
Tomorrow 10:00 am
weather icon
21° | 21°°C 0 mm 0% 6 mph 44 % 1028 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
25° | 25°°C 0 mm 0% 8 mph 31 % 1026 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€93,015.67
1.94%
Ethereum(ETH)
€2,204.15
6.17%
Tether(USDT)
€0.85
0.01%
XRP(XRP)
€1.93
4.77%
Solana(SOL)
€130.06
3.32%
USDC(USDC)
€0.85
0.01%
Dogecoin(DOGE)
€0.146342
6.89%
Shiba Inu(SHIB)
€0.000010
4.45%
Pepe(PEPE)
€0.000008
8.71%
Scroll to Top