WordPress LiteSpeed Cache Plugin Safety Flaw Exposes Websites to XSS Assaults

Oct 04, 2024Ravie LakshmananWeb site Safety / Vulnerability

A brand new high-severity safety flaw has been disclosed within the LiteSpeed Cache plugin for WordPress that would allow malicious actors to execute arbitrary JavaScript code beneath sure situations.

The flaw, tracked as CVE-2024-47374 (CVSS rating: 7.2), has been described as a saved cross-site scripting (XSS) vulnerability impacting all variations of the plugin as much as and together with 6.5.0.2.

It was addressed in model 6.5.1 on September 25, 2024, following accountable disclosure by Patchstack Alliance researcher TaiYou.

“It could allow any unauthenticated user from stealing sensitive information to, in this case, privilege escalation on the WordPress site by performing a single HTTP request,” Patchstack mentioned in a report.

Cybersecurity

The flaw stems from the style through which the plugin the “X-LSCACHE-VARY-VALUE” HTTP header worth is parsed with out satisfactory sanitization and output escaping, thereby permitting for injection of arbitrary net scripts.

That mentioned, it is value declaring that the Web page Optimization settings “CSS Combine” and “Generate UCSS” are required to allow the exploit to achieve success.

Additionally known as persistent XSS assaults, such vulnerabilities make it potential to retailer an injected script completely on the goal web site’s servers, similar to in a database, in a message discussion board, in a customer log, or in a remark.

This causes the malicious code embedded throughout the script to be executed each time an unsuspecting web site customer lands on the requested useful resource, for example, the online web page containing the specifically crafted remark.

Saved XSS assaults can have severe penalties as they may very well be weaponized to ship browser-based exploits, steal delicate info, and even hijack an authenticated person’s session and carry out actions on their behalf.

Probably the most damaging situation is when the hijacked person account is that of a web site administrator, thereby permitting a risk actor to fully take management of the web site and stage much more highly effective assaults.

WordPress plug-ins and themes are a well-liked avenue for cybercriminals trying to compromise authentic web sites. With LiteSpeed Cache boasting over six million lively installations, flaws within the plugin pose a profitable assault floor for opportunistic assaults.

The most recent patch arrives almost a month after the plugin builders addressed one other flaw (CVE-2024-44000, CVSS rating: 7.5) that would enable unauthenticated customers to take management of arbitrary accounts.

Cybersecurity

It additionally follows the disclosure of an unpatched important SQL injection flaw within the TI WooCommerce Wishlist plugin (CVE-2024-43917, CVSS rating: 9.8) that, if efficiently exploited, permits any person to execute arbitrary SQL queries within the database of the WordPress web site.

One other important safety vulnerability issues the Jupiter X Core WordPress plugin (CVE-2024-7772, CVSS rating: 9.8) that permits unauthenticated attackers to add arbitrary information on the affected web site’s server, doubtlessly resulting in distant code execution.

It has been fastened in model 4.7.8, together with a high-severity authentication bypass flaw (CVE-2024-7781, CVSS rating: 8.1) that “makes it possible for unauthenticated attackers to log in as the first user to have logged in with a social media account, including administrator accounts,” Wordfence mentioned.

Discovered this text fascinating? Observe us on Twitter and LinkedIn to learn extra unique content material we put up.

Recent articles

Astaroth Banking Malware Resurfaces in Brazil by way of Spear-Phishing Assault

Oct 16, 2024Ravie LakshmananCyber Assault / Banking Trojan A brand...

GitHub Patches Crucial Flaw in Enterprise Server Permitting Unauthorized Occasion Entry

Oct 16, 2024Ravie LakshmananEnterprise Safety / Vulnerability GitHub has launched...

New Linux Variant of FASTCash Malware Targets Fee Switches in ATM Heists

Oct 15, 2024Ravie LakshmananMonetary Fraud / Linux North Korean risk...

Amazon says 175 million buyer now use passkeys to log in

Amazon has seen large adoption of passkeys for the...