CVE-2024-28000
The LiteSpeed Cache plugin for WordPress through version 6.3.0.1 contains a privilege escalation vulnerability stemming from inadequate controls on role simulation functionality. An attacker who obtains a valid hash from debug logs or successfully brute forces one can impersonate an administrator account and leverage the /wp-json/wp/v2/users REST API endpoint to create new administrative user accounts, even without authentication. The vulnerability may be unexploitable in certain configurations where the crawler feature is disabled.
Based on public CVE data (MITRE/NVD).