{"id":169390,"date":"2024-10-05T13:48:37","date_gmt":"2024-10-05T13:48:37","guid":{"rendered":"https:\/\/securityaffairs.com\/?p=169390"},"modified":"2024-10-05T13:49:35","modified_gmt":"2024-10-05T13:49:35","slug":"wordpress-litespeed-cache-plugin-flaw-site-takeover","status":"publish","type":"post","link":"https:\/\/securityaffairs.com\/169390\/security\/wordpress-litespeed-cache-plugin-flaw-site-takeover.html","title":{"rendered":"WordPress LiteSpeed Cache plugin flaw could allow site takeover"},"content":{"rendered":"
<\/div>\n

A high-severity flaw in the WordPress LiteSpeed Cache plugin could allow attackers to execute arbitrary JavaScript code under certain conditions.<\/h2>\n\n\n\n

A high-severity security flaw, tracked as CVE-2024-47374 (CVSS score 7.2), in the LiteSpeed Cache plugin for WordPress could allow attackers to execute arbitrary JavaScript.<\/p>\n\n\n\n

The vulnerability is a stored cross-site scripting (XSS) issue impacting versions up to 6.5.0.2.<\/p>\n\n\n\n

This LiteSpeed Cache plugin is an all-in-one site acceleration tool, offering server-level caching and optimization features. It supports WordPress Multisite and is compatible with popular plugins like WooCommerce, bbPress, and Yoast SEO. LiteSpeed Cache<\/a> has over six million active installations, for this reason, site admins must address the issue as soon as possible.<\/gwmw><\/p>\n\n\n\n

The vulnerability\u00a0was originally reported by\u00a0TaiYou<\/a>\u00a0to the\u00a0Patchstack bug bounty program for WordPress<\/a>.\u00a0<\/em><\/p>\n\n\n\n

“This plugin suffers from unauthenticated stored XSS vulnerability. It could allow any unauthenticated user from stealing sensitive information to, in this case, privilege escalation on the WordPress site by performing a single HTTP request.” reads<\/a> the advisory.<\/em><\/p>\n\n\n\n

The flaw arises from improper sanitization of the “X-LSCACHE-VARY-VALUE” HTTP header, allowing arbitrary script injection. The issue could be exploited only if the “CSS Combine” and “Generate UCSS” settings are enabled. <\/p>\n\n\n\n

An attacker could potentially exploit this vulnerability to hijack the account of a site administrator and take full control of the website.<\/p>\n\n\n\n

The vulnerability was addressed in version 6.5.1 on September 25, 2024.<\/gwmw><\/p>\n\n\n\n

The most damaging scenario is when the hijacked user account is that of a site administrator, thereby allowing a threat actor to completely take control of the website and stage even more powerful attacks.<\/gwmw><\/p>\n\n\n\n

“We recommend applying escaping and sanitization to any message that will be displayed as an admin notice. Depending on the context of the data, we recommend using\u00a0sanitize_text_field<\/a>\u00a0to sanitize value for HTML output (outside of HTML attribute) or\u00a0esc_html<\/a>. For escaping values inside of attributes, you can use the\u00a0esc_attr\u00a0<\/a>function.” concludes the report. “We also recommend applying a proper permission or authorization check to the registered rest route endpoints.”<\/em><\/gwmw><\/p>\n\n\n\n

In early September, the developer behind the LiteSpeed Cache plugin addressed<\/strong><\/a> another unauthenticated account takeover vulnerability, tracked as CVE-2024-44000 (CVSS score: 7.5), that can allow any visitor to gain access to logged-in users and potentially escalate privileges to the Administrator level. An attacker can exploit this vulnerability to upload malicious plugins.<\/p>\n\n\n\n

Patchstack researchers explained that the flaw stems from an HTTP response header leak that exposed \u201cSet-Cookie\u201d headers in a debug log file (\/wp-content\/debug.log<\/code>) after login attempts.<\/p>\n\n\n\n

An unauthenticated attacker can view sensitive information, including user cookie data from HTTP response headers. This could enable attackers to log in using any valid session. The flaw can be exploited only if the WordPress site\u2019s debug feature is enabled and this feature is disabled by default.<\/p>\n\n\n\n

\u201cThe vulnerability exploits an HTTP response headers leak on the debug log file which also leaks the \u201cSet-Cookie\u201d header after the users perform a login request.\u201d reads the report<\/a> published by Patchstack. \u201cThe main vulnerable code exists on the function ended<\/code>\u201c<\/em><\/p>\n\n\n\n

The vulnerability CVE-2024-44000 impacts versions before and including 6.4.1. The issue has been addressed in version 6.5.0.1.<\/gwmw><\/p>\n\n\n\n

Pierluigi Paganini<\/strong><\/a><\/p>\n\n\n\n

Follow me on Twitter: @securityaffairs<\/strong><\/a> and Facebook<\/strong><\/a> and Mastodon<\/a><\/p>\n\n\n\n

(<\/strong>SecurityAffairs<\/strong><\/a>\u00a0\u2013<\/strong>\u00a0hacking, WordPress)<\/strong><\/p>\n\n\n\n

<\/p>\n","protected":false},"excerpt":{"rendered":"

A high-severity flaw in the WordPress LiteSpeed Cache plugin could allow attackers to execute arbitrary JavaScript code under certain conditions. A high-severity security flaw, tracked as CVE-2024-47374 (CVSS score 7.2), in the LiteSpeed Cache plugin for WordPress could allow attackers to execute arbitrary JavaScript. The vulnerability is a stored cross-site scripting (XSS) issue impacting versions […]<\/p>\n","protected":false},"author":1,"featured_media":36613,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[3323,55],"tags":[4112,9508,9506,10918,687,841,1533,1004,15354],"class_list":["post-169390","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-breaking-news","category-security","tag-hacking","tag-hacking-news","tag-information-security-news","tag-it-information-security","tag-pierluigi-paganini","tag-security-affairs","tag-security-news","tag-wordpress","tag-wordpress-litespeed-cache-plugin"],"yoast_head":"\n杭州江阴科强工业胶带有限公司