<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/critical-flaw-in-wordpress-litespeed-cache-plugin-patched-urgent-update-required-99w6ae3ya" -->

---
title: Critical Flaw in WordPress LiteSpeed Cache Plugin...
description: A critical unauthenticated privilege escalation vulnerability in the LiteSpeed Cache Plugin for WordPress, affecting over 5 million websites, has been patched....
canonical: https://daily.dev/posts/critical-flaw-in-wordpress-litespeed-cache-plugin-patched-urgent-update-required-99w6ae3ya
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Critical Flaw in WordPress LiteSpeed Cache Plugin Patched: Urgent Update Required | daily.dev
og:description: A critical unauthenticated privilege escalation vulnerability in the LiteSpeed Cache Plugin for WordPress, affecting over 5 million websites, has been patched....
og:url: https://daily.dev/posts/critical-flaw-in-wordpress-litespeed-cache-plugin-patched-urgent-update-required-99w6ae3ya
og:image: https://api.daily.dev/og/posts/99W6aE3yA.png
og:image:alt: Critical Flaw in WordPress LiteSpeed Cache Plugin Patched: Urgent Update Required
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Critical Flaw in WordPress LiteSpeed Cache Plugin Patched: Urgent Update Required

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 3 upvotes · 1 comments

## Summary

A critical unauthenticated privilege escalation vulnerability in the LiteSpeed Cache Plugin for WordPress, affecting over 5 million websites, has been patched. Identified as CVE-2024-28000 with a CVSS score of 9.8, the flaw could allow unauthorized admin access and installation of malicious plugins due to insecure random number generation. Users are urged to update to version 6.4 immediately and check for any unauthorized admin accounts.

## Content

# Critical Privilege Escalation Vulnerability Patched in LiteSpeed Cache Plugin for WordPress

The LiteSpeed Cache Plugin for WordPress, a widely-used tool by over 5 million websites, has recently been patched to fix a critical unauthenticated privilege escalation vulnerability, tracked as CVE-2024-28000. This vulnerability, severe enough to warrant a CVSS score of 9.8, could potentially allow unauthorized users to gain administrator access through brute force attacks.

The issue was reported by John Blackbourn, who was awarded a record bounty of $14,400 in recognition of his efforts. The flaw stems from insecure random number generation and the accumulation of static security values, exposing more than 5 million WordPress sites to significant security risks. Although Windows systems are immune to this vulnerability, users on other operating systems are urged to update immediately to version 6.4 of the plugin.

In addition to the privilege escalation risks, the vulnerability also allowed attackers to potentially upload and install malicious plugins by exploiting weak security in the user simulation feature. To address these issues, the LiteSpeed team has incorporated several robust security measures in the new release.

Given the critical nature of this flaw, it is imperative for all users to update the LiteSpeed Cache plugin to version 6.4 or higher. Moreover, administrators should check for any unrecognized administrator accounts within their systems and remove them if necessary. This incident underscores the importance of robust security algorithms and regular updates to maintain the security of WordPress sites.

## Community discussion

Top comments from developers on daily.dev.

**@wpspeeddoctor** · 0 upvotes

> That's already an old new and LS released patch. No need to click on it.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#webdev](https://daily.dev/tags/webdev), [#wordpress](https://daily.dev/tags/wordpress), [#vulnerability](https://daily.dev/tags/vulnerability)

[View this post on daily.dev](https://daily.dev/posts/critical-flaw-in-wordpress-litespeed-cache-plugin-patched-urgent-update-required-99w6ae3ya)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Critical Flaw in WordPress LiteSpeed Cache Plugin Patched: Urgent Update Required","url":"https://daily.dev/posts/critical-flaw-in-wordpress-litespeed-cache-plugin-patched-urgent-update-required-99w6ae3ya","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/critical-flaw-in-wordpress-litespeed-cache-plugin-patched-urgent-update-required-99w6ae3ya"},"datePublished":"2024-08-22T05:55:08.105Z","dateModified":"2024-08-23T20:12:09.718Z","description":"A critical unauthenticated privilege escalation vulnerability in the LiteSpeed Cache Plugin for WordPress, affecting over 5 million websites, has been patched....","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1dca9138389ebe4698afb775e6bb44ad?_a=AQAEuiZ","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1dca9138389ebe4698afb775e6bb44ad?_a=AQAEuiZ","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":1,"discussionUrl":"https://daily.dev/posts/critical-flaw-in-wordpress-litespeed-cache-plugin-patched-urgent-update-required-99w6ae3ya","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":3},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":1}],"keywords":"security,webdev,wordpress,vulnerability","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Critical Flaw in WordPress LiteSpeed Cache Plugin Patched: Urgent Update Required"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/critical-flaw-in-wordpress-litespeed-cache-plugin-patched-urgent-update-required-99w6ae3ya","comment":[{"@type":"Comment","text":"That’s already an old new and LS released patch. No need to click on it.","datePublished":"2024-09-01T08:06:02.534Z","url":"https://daily.dev/posts/99W6aE3yA#c-kCXEI1N5Y","author":{"@type":"Person","name":"Jaro","url":"https://daily.dev/wpspeeddoctor","image":"https://media.daily.dev/image/upload/s--zeEQdMo8--/f_auto/v1718698249/avatars/avatar_PSHEaQRJMuWifIZvzar8w"}}]}
```

