Even a speed-up plugin can let a burglar in
You install a cache plugin for speed, not for excitement. But in 2024 LiteSpeed Cache was a reminder that every add-on is a potential way in, even one that only speeds the site up.
What happened
LiteSpeed Cache is installed on about 5 million sites. The flaw CVE-2024-28000 let an attacker forge the plugin's internal "key" without logging in and, on that basis, create an administrator account for themselves. From there, it is only a step to full control.
It was not this plugin's first problem; earlier it had a flaw fixed that allowed a malicious script to be injected (stored XSS). The scale of installs makes every such flaw a tasty morsel for bots.
Why it matters
A plugin's popularity cuts both ways: great support and frequent updates, but also a huge target. It pays for an attacker to write a bot for a plugin used by millions of sites.
What to do
- Enable automatic updates for your most important plugins: cache, forms, SEO.
- After a high-profile flaw, check the user list in the panel: has an unknown administrator account appeared.
- Keep only one cache plugin. Several at once means conflict and greater risk.
The simplest advice sounds dull but saves sites: update and check accounts. We do this routinely as part of our care service, see what it covers.
Source: NVD, CVE-2024-28000.