PT-2024-6142 · Unknown · Litespeed Cache
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
LiteSpeed Cache versions 1.9 through 6.3.0.1
Description
An incorrect privilege assignment in the LiteSpeed Cache plugin for WordPress allows unauthenticated remote attackers to escalate privileges and gain administrator access. The issue stems from a weakness in the user simulation functionality, which is protected by an insecurely generated security hash with only one million possible values. Attackers can obtain this hash by brute-forcing it or by retrieving it from debug logs on sites where debug mode is enabled. Once the hash is acquired, an attacker can spoof their user ID to that of an administrator and use the
/wp-json/wp/v2/users API endpoint to create a new administrator account, leading to a complete site takeover. Over 5 million websites are potentially affected.Recommendations
Update LiteSpeed Cache to version 6.4 or higher.
Exploit
Fix
LPE
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Litespeed Cache