"LiteSpeed Cache Plugin Vulnerability Exposes Millions of WordPress Sites to Attacks"
"LiteSpeed Cache Plugin Vulnerability Exposes Millions of WordPress Sites to Attacks"
According to security researchers at Patchstack, a vulnerability in the popular LiteSpeed Cache plugin for WordPress could allow attackers to retrieve user cookies and potentially take over websites. The issue, tracked as CVE-2024-44000, exists because the plugin may include the HTTP response header for set-cookie in the debug log file after a login request. The researchers noted that because the debug log file is publicly accessible, an unauthenticated attacker could access the information exposed in the file and extract any user cookies stored in it.