LiteSpeed Cache Security Patches

LiteSpeed Cache for WordPress Security Patches

Written by

in

,

LiteSpeed Cache for WordPress Security Patches

Last year, we were made aware of two distinct vulnerabilities in the LiteSpeed Cache for WordPress plugin. We patched these vulnerabilities right away, in v5.7 and v5.7.0.1 respectively.

To protect your WordPress sites, please update to the latest version of the LSCache plugin immediately. (As of this writing, the latest version is v6.1.)

If you’d like to know more about these vulnerabilities and their impact, read on.

Stored XSS vulnerability

The first issue, reported by the WordFence team, was a stored cross-site scripting vulnerability that could be exploited by authenticated users via the ESI shortcode functionality. Users with contributor-level and above permissions could potentially inject arbitrary web scripts into pages via the ESI shortcode. These scripts would have been executed whenever a user requested the page.

Impact

Only a small portion of our four million users would have been affected by this vulnerability: those that have ESI enabled, and also have authenticated users with permissions at the Contributor level or higher. ESI is disabled by default.

We recommend those impacted sites upgrade to the plugin version 5.7 or higher to patch this vulnerability.

Timeline

  • August 14, 2023: WordFence alerted us to the issue.
  • August 16, 2023: We made a patch and made it available to power users and testers as a GitHub commit
  • October 10, 2023: We released v5.7 to the WordPress repository
  • October 24, 2023: We added v5.7 to the list of stable releases in our control panel plugins

Broken Access Control vulnerability

The second issue, reported by the Patchstack team, was a broken access control vulnerability that could be exploited by unauthenticated users via the LSCWP API. Attackers could use certain API functions to access attachment URLs and details, and also change the nameserver configuration.

Impact

Because the vulnerability could be triggered by unauthenticated users, all four million installations would have been affected.

We recommend that every site should upgrade to the plugin version 5.7.0.1 or higher to patch this vulnerability.

Timeline

  • October 17, 2023: Patchstack alerted us to the issue.
  • October 19, 2023: We made a patch and made it available to power users and testers as a GitHub commit
  • October 25, 2023: We released v5.7.0.1 to the WordPress repository
  • October 26, 2023: We added v5.7.0.1 to the list of stable releases in our control panel plugins

More Information

We thank WordFence and Patchstack for bringing these issues to our attention. We have long since patched both vulnerabilities, so if you are keeping your LiteSpeed Cache plugin up-to-date, there is nothing you need to do. If you have not updated in a while, we strongly recommend doing so today.

Comments

20 responses to “LiteSpeed Cache Security Patches”

  1. Amy Avatar

    So I updated my version to the new version you’re citing, but I’m still getting the same banner message saying I need to upgrade. Any thoughts on what I should do to fix this?

    1. Lisa Clarke Avatar
      Lisa Clarke

      It doesn’t go away after you dismiss it? That’s odd. Please open a ticket via email to support@quic.cloud so the team can have a look.

  2. Detsje Holtrop Avatar

    Dag,

    Hoe upgrade ik versie 6.1 op mijn website. Ik krijg de melding dat dit noodzakelijk is.

    1. Lisa Clarke Avatar
      Lisa Clarke

      Hello. You can upgrade LiteSpeed Cache the same way that you upgrade every other plugin on your website. It’s no different. The easiest way is to go to Dashboard > Updates > Plugins and upgrade it from there.

  3. eh Avatar
    eh

    although I have removed and then installed the latest version of LiteSpeed Cache, I still see the warning banner about vulnerabilities of this plugin!

    1. Lisa Clarke Avatar
      Lisa Clarke

      I’ll let the team know. In the meantime, does it go away if you dismiss the message?

  4. Jose Dieguez Avatar
    Jose Dieguez

    I can confirm that updating the pluign, does not make the banner go.

    1. Lisa Clarke Avatar
      Lisa Clarke

      Did you dismiss the banner? If you dismissed it and it came back, let us know. Otherwise, it is working as intended. You just need to dismiss the banner and it should go away permanently.

  5. Razeakhar Avatar

    menu not clickable on wordpress please guid me

    1. Lisa Clarke Avatar
      Lisa Clarke

      Sorry to hear that. Sounds like it might be a JavaScript optimization conflict. You can check this guide to help troubleshoot on your own, or contact our support team (support@litespeedtech.com) for assistance.

  6. Rachel Gilles Avatar

    Hi, I created the website , and never used it.
    vulnerability Take over the website. I see gambling and other stuff associated with my email. I don’t have access to the admin. I want to cancel that website, how do I do that.

    1. Lisa Clarke Avatar
      Lisa Clarke

      You will need to contact your hosting provider for that. LiteSpeed doesn’t host your website, so there’s nothing we can do. Sorry!

  7. Andy Avatar

    I have purchased a litespeed cache for my site on wordpress, installed it, but all my pictures and text went bananas, got displaced on the site as a result of it. I had to disable it. Not a happy camper.

    1. Lisa Clarke Avatar
      Lisa Clarke

      I’m sorry to hear LSCWP didn’t work for you right out of the gate. It sounds like you might have a CSS conflict. Sometimes third party CSS files don’t take well to being minimized or combined. Same is true with Javascript. We have some documentation that should help you figure out which file is causing the problem: https://docs.litespeedtech.com/lscache/lscwp/ts-optimize/#finding-conflicts Hope this helps!

  8. chan Avatar

    I installed the latest version of this plugin but there is some lack that it showed coding on my homepage so i need to always monitor my pc even when I reinstall it still appears and i need to refresh every time it happens on WP site.

    1. Lisa Clarke Avatar
      Lisa Clarke

      Oh, sorry! I don’t know what could be causing that. Please open a ticket by emailing support@litespeedtech.com, and the support team can help you out.

  9. niko Avatar

    good afternoon. I have installed the new version plugin on the website https://zaplata.ru , my version is 6.2.0.1

    but there are still warnings that I’m using an older version and asking to upgrade.??

    1. Lisa Clarke Avatar
      Lisa Clarke

      6.2.0.1 is an old version, released almost a year ago. The most current version is 7.0.0.1. If you upgrade to that version, the warning should go away.

  10. Jony Howlader Avatar

    Hi, I have installed Litespeed V7.1 but it says “Please update to the latest version (v6.5+) as soon as possible.

    “.
    How can I do that…?

    1. Lisa Clarke Avatar
      Lisa Clarke

      Are you able to dismiss the notification? I believe that is just an issue with the notification erroneously persisting after an upgrade. If you’re using v7.1, you should be fine to just dismiss the notification. If you can’t make it go away, please let the support team know (support@litespeedtech.com). Apologies for any confusion!

Leave a Reply

Your email address will not be published. Required fields are marked *