Critical LiteSpeed Cache vulnerability puts five million WordPress websites at risk

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Security Vulnerability in LiteSpeed Cache Plugin Allows Attackers to Take Over WordPress Sites

LiteSpeed Cache, a popular plugin used to speed up WordPress websites, has been found to have a critical vulnerability that could allow attackers to take over sites with administrator-level access. The plugin, used on over five million websites, features server-level caching and optimization features.

Security researcher John Blackbourn discovered that LiteSpeed Cache suffers from an unauthenticated privilege escalation flaw. This flaw is tied to the plugin’s user simulation feature, which pre-populates caches for pages on a schedule. The security hash used to protect this feature was found to be generated by a weak random generation method, making it vulnerable to brute-force attacks.

The vulnerability affects LiteSpeed Cache versions 6.3.0.1 and earlier. To address this issue, the LiteSpeed team released version 6.4 on August 13th, which includes a more robust method for generating the security hash.

Blackbourn was rewarded $14,400 for his discovery, the highest bounty ever for WordPress bug hunting. This vulnerability comes on the heels of another flaw affecting over 100,000 WordPress sites in the GiveWP donation plugin, which was patched in version 3.14.2.

Users of LiteSpeed Cache are urged to update to at least version 6.4 to protect their websites from potential attacks. The security of WordPress websites continues to be a priority, with researchers and developers working to address vulnerabilities and keep sites secure.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Trump Administration Bans Foreign-Made Power Generation Equipment Over Cybersecurity Risks

The Trump administration has issued an executive order banning the acquisition of foreign-made technology used to manage electricity and power, citing cybersecurity risks. The...

Iranian Hackers Shut Down UK Power Plant for Four Days in Unprecedented Attack

In a significant escalation of cyber warfare, Iranian hackers successfully shut down a British power plant for four days, marking a notable first for...

New Research Reveals Perturbation Probing Method to Assess LLM Safety Fragility

New Research Unveils Perturbation Probing Method to Assess LLM Safety Fragility Recent advancements in the field of large language models (LLMs) have raised critical questions...

PaperCut NG and MF Vulnerabilities CVE-2026-81578 and CVE-2026-82078 Exploited in the Wild

Critical Vulnerabilities in PaperCut NG and MF Exploited in the Wild On August 27, 2026, PaperCut Software issued an urgent security advisory regarding active exploitation...