Litespeed Cache bug exposes millions of WordPress sites to takeover attacks

Share:

A critical vulnerability in the LiteSpeed Cache WordPress plugin can let attackers take over millions of websites after creating rogue admin accounts.

LiteSpeed Cache is open-source and the most popular WordPress site acceleration plugin, with over 5 million active installations and support for WooCommerce, bbPress, ClassicPress, and Yoast SEO.

The unauthenticated privilege escalation vulnerability (CVE-2024-28000) was found in the plugin’s user simulation feature and is caused by a weak hash check in LiteSpeed Cache up to and including version 6.3.0.1.

Security researcher John Blackbourn submitted the flaw to Patchstack’s bug bounty program on August 1. The LiteSpeed team developed a patch and shipped it with LiteSpeed Cache version 6.4, released on August 13.

Successful exploitation enables any unauthenticated visitors to gain administrator-level access, which can be used to completely take over websites running vulnerable LiteSpeed Cache versions by installing malicious plugins, changing critical settings, redirecting traffic to malicious websites, distributing malware to visitors, or stealing user data.

“We were able to determine that a brute force attack that iterates all 1 million known possible values for the security hash and passes them in the litespeed_hash cookie — even running at a relatively low 3 requests per second — is able to gain access to the site as any given user ID within between a few hours and a week,” explained Patchstack security researcher Rafie Muhammad on Wednesday.

“The only prerequisite is knowing the ID of an Administrator-level user and passing it in the litespeed_role cookie. The difficulty of determining such a user depends entirely on the target site and will succeed with a user ID 1 in many cases.”

While the development team released versions that address this critical security vulnerability last Tuesday, download statistics from WordPress’ official plugin repository show that the plugin has only been downloaded just over 2.5 million times, likely leaving more than half of all websites using it exposed to incoming attacks.

Earlier this year, attackers exploited a LiteSpeed Cache unauthenticated cross-site scripting flaw (CVE-2023-40000) to create rogue administrator users and gain control of vulnerable websites. In May, Automattic’s security team, WPScan, warned that threat actors started scanning for targets in April after seeing over 1.2 million probes from just one malicious IP address.

“We strongly advise users to update their sites with the latest patched version of Litespeed Cache, version 6.4.1 at the time of this writing, as soon as possible. We have no doubts that this vulnerability will be actively exploited very soon,” Wordfence threat intel lead Chloe Chamberland also warned today.

In June, the Wordfence Threat Intelligence team also reported that a threat actor backdoored at least five plugins on WordPress.org and added malicious PHP scripts to create accounts with admin privileges on websites running them.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:17 am, Jan 23, 2025
weather icon 3°C
L: 2° | H: 3°
overcast clouds
Humidity: 91 %
Pressure: 1005 mb
Wind: 9 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 8 km
Sunrise: 7:51 am
Sunset: 4:33 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
2° | 3°°C 1 mm 100% 19 mph 89 % 1005 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
5° | 11°°C 1 mm 100% 24 mph 91 % 1003 mb 0 mm/h
Sat Jan 25 9:00 pm
weather icon
2° | 5°°C 0.25 mm 25% 6 mph 93 % 1011 mb 0.26 mm/h
Sun Jan 26 9:00 pm
weather icon
1° | 7°°C 1 mm 100% 15 mph 95 % 1010 mb 0 mm/h
Mon Jan 27 9:00 pm
weather icon
6° | 9°°C 1 mm 100% 27 mph 89 % 993 mb 0 mm/h
Today 6:00 am
weather icon
3° | 3°°C 0 mm 0% 7 mph 89 % 1005 mb 0 mm/h
Today 9:00 am
weather icon
4° | 4°°C 0 mm 0% 8 mph 87 % 1004 mb 0 mm/h
Today 12:00 pm
weather icon
8° | 8°°C 1 mm 100% 18 mph 83 % 1000 mb 0 mm/h
Today 3:00 pm
weather icon
7° | 7°°C 1 mm 100% 19 mph 71 % 999 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 6°°C 0.8 mm 80% 15 mph 72 % 1003 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 5°°C 0 mm 0% 10 mph 77 % 1004 mb 0 mm/h
Tomorrow 12:00 am
weather icon
6° | 6°°C 0 mm 0% 12 mph 79 % 1002 mb 0 mm/h
Tomorrow 3:00 am
weather icon
9° | 9°°C 1 mm 100% 22 mph 89 % 996 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€98,252.38
-3.28%
Ethereum(ETH)
€3,097.06
-3.24%
XRP(XRP)
€3.02
-1.06%
Tether(USDT)
€0.96
-0.07%
Solana(SOL)
€238.87
-2.31%
Dogecoin(DOGE)
€0.337868
-5.64%
USDC(USDC)
€0.96
0.00%
Shiba Inu(SHIB)
€0.000019
-3.44%
Pepe(PEPE)
€0.000014
-7.18%
Peanut the Squirrel(PNUT)
€0.344416
-4.59%
Scroll to Top