QID 731216

Date Published: 2024-02-29

QID 731216: WordPress LiteSpeed Cache Cross-Site Scripting (XSS) Vulnerability

LiteSpeed Cache for WordPress (LSCWP) is an all-in-one site acceleration plugin featuring an exclusive server-level cache and a collection of optimization features.

CVE-2023-40000 : This plugin suffers from unauthenticated site-wide stored XSS vulnerability and could allow any unauthenticated user from stealing sensitive information to in this case privilege escalation on the WordPress site by performing a single HTTP request. Affected Versions:
WordPress LiteSpeed Cache before 5.7.0.1

QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for LiteSpeed Cache Plugin using Blind Elephant Fingerprint technique.

Successful exploitation of this vulnerability could allow an unauthenticated attackers to stealing sensitive information on the the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to install LiteSpeed Cache 5.7.0.1 or later version to remediate this vulnerability.
    Vendor References

    CVEs related to QID 731216

    Software Advisories
    Advisory ID Software Component Link
    Litespeed-cache URL Logo wordpress.org/plugins/litespeed-cache/#developers