CVE-2024-44000
The LiteSpeed Cache plugin for WordPress versions up to and including 6.4.1 contains a vulnerability where an exposed debug.log file can be accessed by unauthenticated users, potentially revealing sensitive data including active user session cookies. An attacker who obtains valid session information from this publicly accessible log file could hijack authenticated user sessions. This exposure only occurs when the debug feature is explicitly enabled, as it remains disabled in default installations.
Based on public CVE data (MITRE/NVD).