Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.
The flaw lies in improper privilege assignment (CWE-266), which allows a person without any account on the WordPress site to escalate their privileges to administrator level. The attacker does not need to provide any authentication credentials or interact with the victim — the attack is possible remotely over the network (network vector, no user interaction required). An exploit for this vulnerability is publicly available in the Exploit-DB database.
An attacker can obtain full administrative privileges on the WordPress site, which in practice means the ability to take over the website, install malicious software, steal data, or further compromise the infrastructure.
The LiteSpeed Cache plugin must be updated immediately to a version higher than 6.3.0.1. Patch details are available in the vendor's references and in the Patchstack database.
LiteSpeed Cache plugin for WordPress in versions from n/a to 6.3.0.1 inclusive.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLitespeedtech Litespeed Cache
APPLitespeedtech1.9 – 6.4 (excl.)
Related vulnerabilities
LiteSpeed Cache – nieuwierzytelnione przejęcie konta przez ujawnione dane logowania
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows ...
Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Tr...
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpee...
Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cac...