Software updates have been released for #LiteSpeedCache, a #Wordpressplugin, to address a critical vulnerability
The vulnerability is tracked as CVE-2024-44000, and when exploited, allows an attacker to log in as another user to Wordpress
Administrators are advised to patch ASAP
encore et encore...
🩹 LiteSpeed Release v6.5.0.1 ( chagelog https://plugins.trac.wordpress.org/changeset/3146657/litespeed-cache/trunk )
"Critical Account Takeover Vulnerability Patched in LiteSpeed Cache Plugin"
👇
https://patchstack.com/articles/critical-account-takeover-vulnerability-patched-in-litespeed-cache-plugin/
⬇️
"LiteSpeed Cache bug exposes 6 million WordPress sites to takeover attacks
Yet, another critical severity vulnerability has been discovered in LiteSpeed Cache, a caching plugin for speeding up user browsing in over 6 million WordPress sites.
The flaw, tracked as CVE-2024-44000 and categorized as an unauthenticated account takeover issue, was discovered by Patchstack's Rafie Muhammad on August 22, 2024. A fix was made available yesterday with the release of LiteSpeed Cache version 6.5.0.1."
👇
https://www.bleepingcomputer.com/news/security/litespeed-cache-bug-exposes-6-million-wordpress-sites-to-takeover-attacks/
📢 Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors? Through October 14th, researchers can earn up to $31,200, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest. ...Read More