Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisoryidentity-authentication-vulnerability

Critical LiteSpeed Cache Flaw Lets Attackers Create WordPress Admin Accounts

Updated 2mo agoFirst seen Apr 14, 20262 sources

A critical vulnerability in the LiteSpeed Cache plugin for WordPress can let attackers create new user accounts — including administrator accounts — on affected sites, potentially leading to full site takeover. The issue affects unpatched versions prior to 6.4 when the plugin is deployed on Linux-based systems; based on available information, the flaw is not currently believed to be exploitable on Windows-based deployments.

The plugin developer has released a fix in version 6.4, and authorities urged organizations and individuals using WordPress with LiteSpeed Cache to update immediately because no alternative mitigations are available. While exploitation of this specific flaw had not been observed at the time of reporting, prior vulnerabilities in the same product have been widely exploited, increasing the urgency of patching exposed sites.

Share:
Critical LiteSpeed Cache Flaw Lets Attackers Create WordPress Admin Accounts
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Aug 22, 20242y ago

Traficom warns of critical LiteSpeed Cache vulnerability

Finland's Traficom issued an alert about a critical vulnerability in LiteSpeed Cache versions prior to 6.4 on Linux-based systems. At the time of the alert, exploitation had not been observed and no mitigations other than updating were available.

LiteSpeed Cache 6.4 released to fix critical WordPress plugin flaw

The developers of the LiteSpeed Cache WordPress plugin released version 6.4 to remediate a critical vulnerability affecting Linux-based deployments. The flaw could allow attackers to create WordPress accounts, including administrator accounts, leading to full site takeover.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Critical LiteSpeed Cache Flaw Lets Attackers Create WordPress Admin Accounts | Mallory