PT-2024-6142 · Unknown · Litespeed Cache

·

CVE-2024-28000

·

Published

2024-08-21

·

Updated

2026-08-30

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LiteSpeed Cache versions 1.9 through 6.3.0.1
Description An incorrect privilege assignment in the LiteSpeed Cache plugin for WordPress allows unauthenticated remote attackers to escalate privileges and gain administrator access. The issue stems from a weakness in the user simulation functionality, which is protected by an insecurely generated security hash with only one million possible values. Attackers can obtain this hash by brute-forcing it or by retrieving it from debug logs on sites where debug mode is enabled. Once the hash is acquired, an attacker can spoof their user ID to that of an administrator and use the /wp-json/wp/v2/users API endpoint to create a new administrator account, leading to a complete site takeover. Over 5 million websites are potentially affected.
Recommendations Update LiteSpeed Cache to version 6.4 or higher.

Exploit

Fix

LPE

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07061
CVE-2024-28000

Affected Products

Litespeed Cache