Threat Advisory

Critical Flaw in LiteSpeed Cache Allows Unauthenticated Account Takeover

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical vulnerability, CVE-2024-44000, has been discovered in the LiteSpeed Cache plugin for WordPress. This flaw allows unauthenticated users to potentially take over arbitrary accounts by exploiting a publicly exposed debug log file. The log file may contain sensitive information such as user cookies, enabling attackers to gain unauthorized access, including administrative privileges, on vulnerable sites. The issue arises if the debug feature is enabled, or if sites that had this feature activated have not removed the debug file. The vulnerability has been mitigated by relocating the log file to a more secure directory, randomizing filenames, and removing the logging of cookies. It is advised to check for the presence of the debug log file, remove it if found, and implement .htaccess rules to deny direct access to log files.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical vulnerability, CVE-2024-44000, has been discovered in the LiteSpeed Cache plugin for WordPress. This flaw allows unauthenticated users to potentially take over arbitrary accounts by exploiting a publicly exposed debug log file. The log file may contain sensitive information such as user cookies, enabling attackers to gain unauthorized access, including administrative privileges, on vulnerable sites. The issue arises if the debug feature is enabled, or if sites that had this feature activated have not removed the debug file. The vulnerability has been mitigated by relocating the log file to a more secure directory, randomizing filenames, and removing the logging of cookies. It is advised to check for the presence of the debug log file, remove it if found, and implement .htaccess rules to deny direct access to log files.[emaillocker id="1283"]

RECOMMENDATION:

  • We strongly recommend you update the LiteSpeed Cache Plugin to version 6.5.0.1.

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/09/critical-security-flaw-found-in.html

[/emaillocker]
crossmenu