"Critical LiteSpeed Cache Plugin Flaw Exposes WordPress Sites"
"Critical LiteSpeed Cache Plugin Flaw Exposes WordPress Sites"
A security researcher named John Blackbourn, through the Patchstack zero-day bug bounty program, has discovered a critical vulnerability in the LiteSpeed Cache plugin, potentially exposing millions of WordPress sites to severe security risks. The researcher noted that the vulnerability allows unauthorized users to gain administrator-level access and could lead to installing malicious plugins and compromising affected websites. The researcher said the vulnerability arises from the plugin’s weak security hash used in its user simulation feature.