Property Abroad
Blog
The LiteSpeed Cache plugin for WordPress is actively used in the wild.

The LiteSpeed Cache plugin for WordPress is actively used in the wild.

The LiteSpeed Cache plugin for WordPress is actively used in the wild.

Recent studies have shown that attackers are actively exploiting a serious vulnerability in the LiteSpeed Cache plugin for WordPress, allowing them to take control of websites. Researchers from WPScan reported that this vulnerability is designated asCVE-2023-40000and has a CVSS score of8.3This is characteristic of insufficient input data sanitization during the generation of web pages, which leads to the possibility of XSS attacks (cross-site scripting) on web resources utilizing LiteSpeed Cache.

Plugin description

The LiteSpeed Cache plugin for WordPress (LSCWP) is a versatile tool for speeding up websites and features unique server-side caching along with numerous optimization functions. Since its release, it has been installed on more than5 millionWhile studying this vulnerability, experts discovered that attackers can create fake administrator accounts with nameswpsupp-userandwp-configuseron hacked resources. These accounts allow for complete control over the site.

Progress of research

A vulnerability was identified inFebruary 2024Experts from Patchstack have reported that the exploitation process of this vulnerability can be initiated by an unauthenticated user who uses carefully crafted HTTP requests to escalate their privileges.

Buy in Turkey for 1951100€
2 263 532 $
4
4
289
Buy in Turkey for 6581900€
7 635 868 $
46
46
1799
2
2
82.88
Buy in Turkey for 195000$
195 000 $
1
1
49.54
1
50
2
2
87.25
WPScan also noted that attackers can inject malicious scripts into vulnerable versions of the LiteSpeed plugin. During the monitoring of attacks, a significant increase in requests to fraudulent URLs was observed on April 2 and April 27.

Active IP addresses

Research has shown that the most active IP addresses have been identified, which likely scanned vulnerable websites. These addresses include:

  • 94.102.51.144with more than 1.2 million requests
  • 31.43.191.220with more than 70 thousand requests

The vulnerability has been fixed inOctober 2023with the release of the version5.7.0.1These studies also highlighted indicators of compromise related to these attacks, including fraudulent URLs.

Recommendations from researchers

Researchers also strongly recommend being cautious of IP addresses associated with malware, for example45.150.67.235Stay updated with the latest news and updates in the field of cybersecurity by following me on Twitter: @securityaffairs, as well as on Facebook and Mastodon. Be careful and protect your resources from potential threats!

We will find property in Turkey for you

  • 🔸 Reliable new buildings and ready-made apartments
  • 🔸 Without commissions and intermediaries
  • 🔸 Online display and remote transaction

Subscribe to the newsletter from Hatamatata.com!

I agree to the processing of personal data and confidentiality rules of Hatamatata

Popular Offers

Buy in Turkey for 1690000€
1 960 622 $
6
541
4
185
4
260

Need advice on your situation?

Get a  free  consultation on purchasing real estate overseas. We’ll discuss your goals, suggest the best strategies and countries, and explain how to complete the purchase step by step. You’ll get clear answers to all your questions about buying, investing, and relocating abroad.

Vector Bg
Irina

Irina Nikolaeva

Sales Director, HataMatata