vulnerability

WordPress Plugin: litespeed-cache: CVE-2024-50550: Incorrect Privilege Assignment

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
Oct 29, 2024
Added
May 15, 2025
Modified
Jul 9, 2025

Description

The LiteSpeed Cache plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.1. This is due to the is_role_simulation() function not properly providing protection against unauthorized use of the function. This makes it possible for unauthenticated attackers to simulate roles such as administrators which provides elevated access to the site. Please note there are a lot of pre-requisites for this to be exploitable.

Solution

litespeed-cache-plugin-cve-2024-50550
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.