Rewterz
Multiple Google Chrome Vulnerabilities
September 20, 2024
Rewterz
Bitter APT – Active IOCs
September 20, 2024

Multiple WordPress Plugins Vulnerabilities

Severity

High

Analysis Summary

CVE-2024-44000 CVSS:9.8

LiteSpeed Technologies LiteSpeed Cache Plugin for WordPress could allow a remote attacker to gain elevated privileges on the system, caused by an HTTP response headers leak on the debug log file which also leaks the “Set-Cookie” header after the users perform a login request. By sending a specially crafted request, an attacker could exploit this vulnerability to gain Administrator level access after which malicious plugins could be uploaded and installed.

CVE-2024-5932 CVSS:10

GiveWP Plugin for WordPress could allow a remote attacker to execute arbitrary code on the system, caused by a PHP object injection vulnerability. By using deserialization of untrusted input from the 'give_title' parameter, an attacker could exploit this vulnerability to inject a PHP Object and execute arbitrary code on the system.

Impact

  • Privilege Escalation
  • Code Execution

Indicators of Compromise

CVE

  • CVE-2024-44000
  • CVE-2024-5932

Affected Vendors

WordPress

Affected Products

  • GiveWP Plugin for WordPress 3.14.1
  • LiteSpeed Technologies LiteSpeed Cache - 6.5.0.0

Remediation

Upgrade to the latest version of Plugin for WordPress, available from the WordPress Website.

CVE-2024-44000

CVE-2024-5932