First published: Wed Aug 21 2024(Updated: )
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from 1.9 through 6.3.0.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
LiteSpeed Cache | >=1.9<6.3.0.1 | |
LiteSpeed Cache | <=6.3.0.1 | |
LiteSpeed Technologies LiteSpeed Cache | >=1.9<6.4 |
Update to 6.4 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28000 is a critical vulnerability that allows privilege escalation in LiteSpeed Cache.
CVE-2024-28000 affects LiteSpeed Cache versions from 1.9 through 6.3.0.1.
To fix CVE-2024-28000, upgrade LiteSpeed Cache to the latest version beyond 6.3.0.1.
CVE-2024-28000 can potentially allow attackers to escalate their privileges and take control of affected WordPress sites.
Yes, a patch has been released that addresses CVE-2024-28000, which can be applied by updating the LiteSpeed Cache plugin.