vulnerability
WordPress Plugin: litespeed-cache: CVE-2024-50550: Incorrect Privilege Assignment
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 9 | (AV:N/AC:M/Au:N/C:C/I:C/A:C) | Oct 29, 2024 | May 15, 2025 | Jul 9, 2025 |
Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
Oct 29, 2024
Added
May 15, 2025
Modified
Jul 9, 2025
Description
The LiteSpeed Cache plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.1. This is due to the is_role_simulation() function not properly providing protection against unauthorized use of the function. This makes it possible for unauthenticated attackers to simulate roles such as administrators which provides elevated access to the site. Please note there are a lot of pre-requisites for this to be exploitable.
Solution
litespeed-cache-plugin-cve-2024-50550
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.