CVE-2024-44000

WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability

Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a before 6.5.0.1.


We have discovered 216,182 live websites that are affected by CVE-2024-44000.

Test my site




Affected Software

Product  Litespeed Cache
Category Cache Tools
Vulnerable Domains216,182 live websites (23.56% of Litespeed Cache install base)
Vulnerable Versions
  • from 0 before 6.5.0.1
Vulnerable Versions Count149 versions ( 95.51% of all versions)


Common Weakness Enumeration

CWE-522 Insufficiently Protected Credentials



Details

  • Published - Oct 20, 2024
  • Updated - Oct 21, 2024

Credits

  • Rafie Muhammad (Patchstack) (finder)

CVE-2024-44000 usage by Country

United States72,350 websites



Poland14,435 websites
GB13,270 websites
Germany11,197 websites
France10,621 websites
Turkey9,361 websites
Canada8,817 websites
Spain7,075 websites
Romania6,002 websites
Vietnam5,532 websites

CVE-2024-44000 usage by TLD

.com97,907 websites
.pl11,295 websites
.org9,037 websites
.net6,502 websites
.co.uk6,367 websites
.com.br6,247 websites
.com.au4,160 websites
.es3,299 websites
.ca3,222 websites
.nl2,851 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-44000

Top websites that are affected by CVE-2024-44000. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.fm United States*,***
***********.com Austria*,***
***************************.***.mx United States*,***
*********.com France*,***
*********.***********.eu Germany**,***
***********.net United States**,***
*******.net United States**,***
*******.net United States**,***
*******.com United States**,***
*****.co United States**,***
See full domain list

FAQ

CVE-2024-44000 is Insufficiently Protected Credentials in Litespeed Cache
A total of 216,182 websites have been identified as vulnerable to CVE-2024-44000, discovered through global website indexing conducted by WebTechSurvey.
Litespeed Cache is susceptible to CVE-2024-44000 vulnerability.
Litespeed Cache versions before 6.5.0.1 are vulnerable to CVE-2024-44000.
Version 6.5.0.1 of Litespeed Cache addresses the CVE-2024-44000 security vulnerability.