Litespeed-Cache-Bug macht Millionen von WordPress-Seiten anfällig für Übernahme-Angriffe

Teilen:

A critical vulnerability in the LiteSpeed Cache WordPress plugin can let attackers take over millions of websites after creating rogue admin accounts.

LiteSpeed Cache is open-source and the most popular WordPress site acceleration plugin, with over 5 million active installations and support for WooCommerce, bbPress, ClassicPress, and Yoast SEO.

The unauthenticated privilege escalation vulnerability (CVE-2024-28000) was found in the plugin’s user simulation feature and is caused by a weak hash check in LiteSpeed Cache up to and including version 6.3.0.1.

Security researcher John Blackbourn submitted the flaw to Patchstack’s bug bounty program on August 1. The LiteSpeed team developed a patch and shipped it with LiteSpeed Cache version 6.4, released on August 13.

Successful exploitation enables any unauthenticated visitors to gain administrator-level access, which can be used to completely take over websites running vulnerable LiteSpeed Cache versions by installing malicious plugins, changing critical settings, redirecting traffic to malicious websites, distributing malware to visitors, or stealing user data.

“We were able to determine that a brute force attack that iterates all 1 million known possible values for the security hash and passes them in the litespeed_hash cookie — even running at a relatively low 3 requests per second — is able to gain access to the site as any given user ID within between a few hours and a week,” explained Patchstack security researcher Rafie Muhammad on Wednesday.

“The only prerequisite is knowing the ID of an Administrator-level user and passing it in the litespeed_role cookie. The difficulty of determining such a user depends entirely on the target site and will succeed with a user ID 1 in many cases.”

While the development team released versions that address this critical security vulnerability last Tuesday, download statistics from WordPress’ official plugin repository show that the plugin has only been downloaded just over 2.5 million times, likely leaving more than half of all websites using it exposed to incoming attacks.

Earlier this year, attackers exploited a LiteSpeed Cache unauthenticated cross-site scripting flaw (CVE-2023-40000) to create rogue administrator users and gain control of vulnerable websites. In May, Automattic’s security team, WPScan, warned that threat actors started scanning for targets in April after seeing over 1.2 million probes from just one malicious IP address.

“We strongly advise users to update their sites with the latest patched version of Litespeed Cache, version 6.4.1 at the time of this writing, as soon as possible. We have no doubts that this vulnerability will be actively exploited very soon,” Wordfence threat intel lead Chloe Chamberland also warned today.

In June, the Wordfence Threat Intelligence team also reported that a threat actor backdoored at least five plugins on WordPress.org and added malicious PHP scripts to create accounts with admin privileges on websites running them.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:33 am, März 27, 2025
Wetter-Symbol 7°C
L: 5° | H: 8°
wenige Wolken
Luftfeuchtigkeit: 85 %
Druck: 1024 mb
Wind: 3 mph SSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 19%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:46 am
Sonnenuntergang: 6:24 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
5° | 8°°C 0 mm 0% 9 mph 91 % 1024 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
7° | 12°°C 1 mm 100% 13 mph 93 % 1015 mb 0 mm/h
Sa. März 29 9:00 pm
Wetter-Symbol
4° | 12°°C 0 mm 0% 9 mph 78 % 1023 mb 0 mm/h
So. März 30 9:00 pm
Wetter-Symbol
7° | 17°°C 0 mm 0% 10 mph 82 % 1024 mb 0 mm/h
Mo. März 31 9:00 pm
Wetter-Symbol
8° | 15°°C 0 mm 0% 8 mph 86 % 1028 mb 0 mm/h
Today 3:00 am
Wetter-Symbol
8° | 9°°C 0 mm 0% 4 mph 88 % 1024 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
7° | 8°°C 0 mm 0% 4 mph 91 % 1023 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 69 % 1023 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 7 mph 51 % 1021 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 9 mph 47 % 1018 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 7 mph 60 % 1017 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
12° | 12°°C 0 mm 0% 6 mph 78 % 1017 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 7 mph 82 % 1015 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€81,218.33
-0.69%
Ethereum(ETH)
€1,880.93
-2.62%
Fesseln(USDT)
€0.93
-0.01%
XRP(XRP)
€2.20
-4.33%
Solana(SOL)
€128.59
-4.30%
USDC(USDC)
€0.93
0.00%
Dogecoin(DOGE)
€0.182195
0.59%
Shiba Inu(SHIB)
€0.000013
2.22%
Pepe(PEPE)
€0.000008
6.23%
Peanut das Eichhörnchen(PNUT)
€0.214428
7.85%
Nach oben scrollen