Litespeed-Cache-Bug macht Millionen von WordPress-Seiten anfällig für Übernahme-Angriffe

Teilen:

A critical vulnerability in the LiteSpeed Cache WordPress plugin can let attackers take over millions of websites after creating rogue admin accounts.

LiteSpeed Cache is open-source and the most popular WordPress site acceleration plugin, with over 5 million active installations and support for WooCommerce, bbPress, ClassicPress, and Yoast SEO.

The unauthenticated privilege escalation vulnerability (CVE-2024-28000) was found in the plugin’s user simulation feature and is caused by a weak hash check in LiteSpeed Cache up to and including version 6.3.0.1.

Security researcher John Blackbourn submitted the flaw to Patchstack’s bug bounty program on August 1. The LiteSpeed team developed a patch and shipped it with LiteSpeed Cache version 6.4, released on August 13.

Successful exploitation enables any unauthenticated visitors to gain administrator-level access, which can be used to completely take over websites running vulnerable LiteSpeed Cache versions by installing malicious plugins, changing critical settings, redirecting traffic to malicious websites, distributing malware to visitors, or stealing user data.

“We were able to determine that a brute force attack that iterates all 1 million known possible values for the security hash and passes them in the litespeed_hash cookie — even running at a relatively low 3 requests per second — is able to gain access to the site as any given user ID within between a few hours and a week,” explained Patchstack security researcher Rafie Muhammad on Wednesday.

“The only prerequisite is knowing the ID of an Administrator-level user and passing it in the litespeed_role cookie. The difficulty of determining such a user depends entirely on the target site and will succeed with a user ID 1 in many cases.”

While the development team released versions that address this critical security vulnerability last Tuesday, download statistics from WordPress’ official plugin repository show that the plugin has only been downloaded just over 2.5 million times, likely leaving more than half of all websites using it exposed to incoming attacks.

Earlier this year, attackers exploited a LiteSpeed Cache unauthenticated cross-site scripting flaw (CVE-2023-40000) to create rogue administrator users and gain control of vulnerable websites. In May, Automattic’s security team, WPScan, warned that threat actors started scanning for targets in April after seeing over 1.2 million probes from just one malicious IP address.

“We strongly advise users to update their sites with the latest patched version of Litespeed Cache, version 6.4.1 at the time of this writing, as soon as possible. We have no doubts that this vulnerability will be actively exploited very soon,” Wordfence threat intel lead Chloe Chamberland also warned today.

In June, the Wordfence Threat Intelligence team also reported that a threat actor backdoored at least five plugins on WordPress.org and added malicious PHP scripts to create accounts with admin privileges on websites running them.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:21 am, Jan. 23, 2025
Wetter-Symbol 2°C
L: 1° | H: 3°
overcast clouds
Luftfeuchtigkeit: 91 %
Druck: 1004 mb
Wind: 6 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 85%
Regen Chance: 0%
Sichtbarkeit: 7 km
Sonnenaufgang: 7:51 am
Sonnenuntergang: 4:33 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
1° | 3°°C 1 mm 100% 19 mph 90 % 1005 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
5° | 11°°C 1 mm 100% 24 mph 91 % 1003 mb 0 mm/h
Sa. Jan. 25 9:00 pm
Wetter-Symbol
2° | 5°°C 0.25 mm 25% 6 mph 93 % 1011 mb 0.26 mm/h
So. Jan. 26 9:00 pm
Wetter-Symbol
1° | 7°°C 1 mm 100% 15 mph 95 % 1010 mb 0 mm/h
Mo. Jan. 27 9:00 pm
Wetter-Symbol
6° | 9°°C 1 mm 100% 27 mph 89 % 993 mb 0 mm/h
Today 3:00 am
Wetter-Symbol
2° | 3°°C 0 mm 0% 5 mph 90 % 1004 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
2° | 3°°C 0 mm 0% 7 mph 88 % 1005 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 8 mph 85 % 1004 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
8° | 8°°C 1 mm 100% 18 mph 83 % 1000 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
7° | 7°°C 1 mm 100% 19 mph 71 % 999 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
6° | 6°°C 0.8 mm 80% 15 mph 72 % 1003 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 10 mph 77 % 1004 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
6° | 6°°C 0 mm 0% 12 mph 79 % 1002 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€99,104.46
-2.56%
Ethereum(ETH)
€3,120.68
-2.89%
XRP(XRP)
€3.04
-0.86%
Fesseln(USDT)
€0.96
-0.05%
Solana(SOL)
€245.59
1.14%
Dogecoin(DOGE)
€0.345393
-2.93%
USDC(USDC)
€0.96
0.00%
Shiba Inu(SHIB)
€0.000019
-3.66%
Pepe(PEPE)
€0.000014
-5.67%
Peanut das Eichhörnchen(PNUT)
€0.346133
-3.53%
Nach oben scrollen