Security vulnerability threatening millions of websites discovered!
A security vulnerability has been discovered in LiteSpeed Cache, a popular plugin for WordPress, which could allow hackers to access sensitive information. This flaw, which could affect millions of websites, leaves them vulnerable to cross-site scripting (XSS) attacks.
12punto
It has been revealed that LiteSpeed Cache, a widely used WordPress plugin, contains a security vulnerability that could allow hackers to steal sensitive information.
Security researchers who discovered the flaw note that this plugin, used to improve and optimize website performance, is actively used on more than four million websites. This security vulnerability is identified as a cross-site scripting (XSS) attack and can be exploited via an HTTP request.
The vulnerability stems from the code that processes user input failing to ensure output escaping, and can be combined with improper access control in existing REST API endpoints.
Researchers stated that after the discovery of the vulnerability, the developers of LiteSpeed Cache released a patch. They emphasized that this patch should be applied immediately to ensure users update the plugin and close the security gap.
In this way, users of the plugin will be made more secure against attacks by hackers.