ZeroHour

CVE-2024-44000

mass

Unauthenticated Account Takeover in WordPress LiteSpeed Cache Plugin

CVSS 3.1
9.8 critical
EPSS
82%p100
Published
()
Modified
AI analysis

CVE-2024-44000 is an insufficiently protected credentials flaw (CWE-522) in the LiteSpeed Cache WordPress plugin that permits an authentication bypass, allowing an unauthenticated remote attacker to take over user accounts, including administrators. The weakness affects LiteSpeed Cache versions prior to 6.5.0.1 and is reachable over the network with no privileges or user interaction required (CVSS 9.8). An attacker who exploits it can bypass login protections and gain administrative control of the affected WordPress site, potentially leading to full site takeover. Any WordPress site running a LiteSpeed Cache version below 6.5.0.1 is affected. Exploitation has not been added to CISA's KEV catalog and no public proof-of-concept is known, but an EPSS score of 82.3% (100th percentile) indicates a very high probability of exploitation activity in the next 30 days.

What to do: Upgrade LiteSpeed Cache to version 6.5.0.1 or later immediately, given the unauthenticated, critical-severity nature of the flaw and the very high EPSS score. After patching, review administrator accounts and audit logs for signs of unexpected logins or account takeover, and rotate privileged credentials if compromise is suspected.

Affected
LiteSpeed Technologies LiteSpeed Cacheall versions prior to 6.5.0.1 (from n/a through < 6.5.0.1)
Estimated exposure
mass≈5,000,000+ WordPress sites (plugin has over 5 million active installs) — LiteSpeed Cache is one of the most-installed WordPress plugins, with over 5 million active installs reported on the WordPress plugin directory, so the potentially affected population is on the order of millions of sites.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1.

Vendors
litespeedtech
Products
litespeed cache
Ecosystems
WordPress
Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news