CVE-2024-44000
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
5Exploited in Wild
-Decision
Descriptions
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a before 6.5.0.1.
The LiteSpeed Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.4.1 through the debug.log file that is publicly exposed. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log file. The log file may contain user cookies making it possible for an attacker to log in with any session that is actively valid and exposed in the log file. Note: the debug feature must be enabled for this to be a concern and this feature is disabled by default.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-08-18 CVE Reserved
- 2024-09-05 CVE Published
- 2024-09-06 First Exploit
- 2024-10-21 CVE Updated
- 2024-10-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-522: Insufficiently Protected Credentials
- CWE-532: Insertion of Sensitive Information into Log File
CAPEC
- CAPEC-115: Authentication Bypass
References (7)
URL | Date | SRC |
---|---|---|
https://github.com/absholi7ly/CVE-2024-44000-LiteSpeed-Cache | 2024-09-06 | |
https://github.com/ifqygazhar/CVE-2024-44000-LiteSpeed-Cache | 2024-09-16 | |
https://github.com/gbrsh/CVE-2024-44000 | 2024-09-06 | |
https://github.com/geniuszlyy/CVE-2024-44000 | 2024-10-10 | |
https://github.com/zgimszhd61/CVE-2024-44000 | 2024-10-31 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Litespeed Cache Search vendor "Litespeed Cache" | Litespeed Cache Search vendor "Litespeed Cache" for product "Litespeed Cache" | >= 0.0.0 <= 6.4.1 Search vendor "Litespeed Cache" for product "Litespeed Cache" and version " >= 0.0.0 <= 6.4.1" | en |
Affected
|