May 8, 2024, 7:03 a.m. | info@thehackernews.com (The Hacker News)

The Hacker News thehackernews.com

A high-severity flaw impacting the LiteSpeed Cache plugin for WordPress is being actively exploited by threat actors to create rogue admin accounts on susceptible websites.
The findings come from WPScan, which said that the vulnerability (CVE-2023-40000, CVSS score: 8.3) has been leveraged to set up bogus admin users with the names wpsupp‑user 

accounts actively exploited admin bogus bug cache control cve cvss cvss score exploited exploiting findings flaw hackers high litespeed cache plugin plugin rogue rogue admin score severity threat threat actors vulnerability websites wordpress wordpress sites wpscan

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Computer and Forensics Investigator

@ ManTech | 221BQ - Cstmr Site,Springfield,VA

Senior Security Analyst

@ Oracle | United States

Associate Vulnerability Management Specialist

@ Diebold Nixdorf | Hyderabad, Telangana, India