CVE · Critical

CVE-2024-44000 — LiteSpeed Cache [litespeed-cache] < 6.5.0.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-44000 LiteSpeed Cache [litespeed-cache] < 6.5.0.1 Insufficiently Protected Credentials Critical 9.8 < 6.5.0.1 6.5.0.1 2024-09-05

CVE-2024-44000

The LiteSpeed Cache plugin for WordPress versions up to and including 6.4.1 contains a vulnerability where an exposed debug.log file can be accessed by unauthenticated users, potentially revealing sensitive data including active user session cookies. An attacker who obtains valid session information from this publicly accessible log file could hijack authenticated user sessions. This exposure only occurs when the debug feature is explicitly enabled, as it remains disabled in default installations.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.