Security

Even a speed-up plugin can let a burglar in

Even a speed-up plugin can let a burglar in

You install a cache plugin for speed, not for excitement. But in 2024 LiteSpeed Cache was a reminder that every add-on is a potential way in, even one that only speeds the site up.

What happened

LiteSpeed Cache is installed on about 5 million sites. The flaw CVE-2024-28000 let an attacker forge the plugin's internal "key" without logging in and, on that basis, create an administrator account for themselves. From there, it is only a step to full control.

It was not this plugin's first problem; earlier it had a flaw fixed that allowed a malicious script to be injected (stored XSS). The scale of installs makes every such flaw a tasty morsel for bots.

Why it matters

A plugin's popularity cuts both ways: great support and frequent updates, but also a huge target. It pays for an attacker to write a bot for a plugin used by millions of sites.

What to do

  • Enable automatic updates for your most important plugins: cache, forms, SEO.
  • After a high-profile flaw, check the user list in the panel: has an unknown administrator account appeared.
  • Keep only one cache plugin. Several at once means conflict and greater risk.

The simplest advice sounds dull but saves sites: update and check accounts. We do this routinely as part of our care service, see what it covers.

Source: NVD, CVE-2024-28000.

Related articles

Related services

Free security audit

Do not wait for the site to go down

Send us your website address through the form. We will check it for threats and performance, and you get concrete recommendations plus a free security quote.

Request a free audit →

No obligation · Contact via the form · Reply within 1 business day

Looking for a fresh start? We will build your site from scratch, fast and secure. See the MP WebSolutions offer.