Tag: LiteSpeed Cache Bug

Hackers Exploiting LiteSpeed Cache Bug to Gain Full Control of WordPress Sites
News

Hackers Exploiting LiteSpeed Cache Bug to Gain Full Control of WordPress Sites

Threat actors are actively using a high-severity vulnerability in the WordPress plugin LiteSpeed Cache to create rogue administrator accounts on vulnerable websites. The information was obtained via WPScan, which reported that phony admin users with the identities wpsupp‑user and wp‑configuser had been created using the vulnerability (CVE-2023-40000, CVSS score: 8.3). Patchstack discovered CVE-2023-40000, a stored cross-site scripting (XSS) vulnerability that might allow an unauthorized user to escalate privileges through carefully constructed HTTP requests. Version 5.7.0.1 was released in October 2023, fixing the vulnerability. It's important to remember that the plugin was last updated read more Hackers Exploiting LiteSpeed Cache Bug to Gain Full Control of WordPress Sites. ...