CVE-2024-44000: WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
Published Oct 20, 2024
·Updated
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1.
Affected Software
1 affected component
Litespeedtech Litespeed Cache Wordpress<6.5.0.1
Remediation
Information
Update to 6.5.0.1 or a higher version.
Event History
Sep 5, 2024
News Published
via BleepingComputer·04:58 PM
News Published
via BleepingComputer·06:01 PM
Oct 20, 2024
CVE Published
via MITRE·11:26 AM
Data Sourced
via MITRE·11:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Oct 31, 2024
News Published
via BleepingComputer·04:19 PM
Mar 28, 2025
Exploit Published
12:00 AM
Known Exploited
05:41 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-44000?
CVE-2024-44000 has a high severity rating due to its potential for authentication bypass and account takeover.
2
How do I fix CVE-2024-44000?
To fix CVE-2024-44000, update LiteSpeed Cache to version 6.5.0.1 or later.
3
What types of systems are affected by CVE-2024-44000?
CVE-2024-44000 affects LiteSpeed Cache versions up to 6.5.0.1 used in WordPress.
4
What consequences can occur due to CVE-2024-44000?
Exploitation of CVE-2024-44000 can lead to unauthorized access and control over WordPress sites.
5
Is there any mitigation for CVE-2024-44000 if I cannot update?
Temporary mitigation for CVE-2024-44000 includes restricting access to administrative areas until an update is applied.