CVE · High

CVE-2024-50550 — LiteSpeed Cache [litespeed-cache] < 6.5.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-50550 LiteSpeed Cache [litespeed-cache] < 6.5.2 Incorrect Privilege Assignment High 8.1 < 6.5.2 6.5.2 2024-10-29

CVE-2024-50550

The LiteSpeed Cache plugin for WordPress before version 6.5.2 contains a privilege escalation vulnerability in the is_role_simulation() function that fails to adequately restrict access to the function. This flaw permits unauthenticated users to impersonate administrator roles and gain elevated privileges on the affected site, though successful exploitation requires certain prerequisite conditions to be present.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.