CVE · Critical

CVE-2024-28000 — LiteSpeed Cache [litespeed-cache] < 6.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-28000 LiteSpeed Cache [litespeed-cache] < 6.4 Incorrect Privilege Assignment Critical 9.8 < 6.4 6.4 2024-08-19

CVE-2024-28000

The LiteSpeed Cache plugin for WordPress through version 6.3.0.1 contains a privilege escalation vulnerability stemming from inadequate controls on role simulation functionality. An attacker who obtains a valid hash from debug logs or successfully brute forces one can impersonate an administrator account and leverage the /wp-json/wp/v2/users REST API endpoint to create new administrative user accounts, even without authentication. The vulnerability may be unexploitable in certain configurations where the crawler feature is disabled.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.