CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-28000

CVSS 9.8v3.1pub. 2024-08-21upd. 2026-04-29

Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.

🤖 AI Analysis
How it works

The flaw lies in improper privilege assignment (CWE-266), which allows a person without any account on the WordPress site to escalate their privileges to administrator level. The attacker does not need to provide any authentication credentials or interact with the victim — the attack is possible remotely over the network (network vector, no user interaction required). An exploit for this vulnerability is publicly available in the Exploit-DB database.

Impact

An attacker can obtain full administrative privileges on the WordPress site, which in practice means the ability to take over the website, install malicious software, steal data, or further compromise the infrastructure.

Mitigation & patch

The LiteSpeed Cache plugin must be updated immediately to a version higher than 6.3.0.1. Patch details are available in the vendor's references and in the Patchstack database.

Who is affected

LiteSpeed Cache plugin for WordPress in versions from n/a to 6.3.0.1 inclusive.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Litespeedtech Litespeed Cache

    APP
    Litespeedtech
    1.9 – 6.4 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2024-44000CRITICAL9.8PL ✓same product

LiteSpeed Cache – nieuwierzytelnione przejęcie konta przez ujawnione dane logowania

CVE-2024-50550HIGH8.1same product

Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows ...

CVE-2024-47637HIGH8.8same product

Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Tr...

CVE-2024-47374HIGH7.1same product

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpee...

CVE-2023-45000HIGH8.2same product

Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cac...