QID 731249

Date Published: 2024-03-13

QID 731249: WordPress LiteSpeed Cache Cross-Site Scripting (XSS) Vulnerability (CVE-2023-4372)

LiteSpeed Cache for WordPress (LSCWP) is an all-in-one site acceleration plugin featuring an exclusive server-level cache and a collection of optimization features.

CVE-2023-4372 : The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the esi shortcode in versions up to and including 5.6 due to insufficient input sanitization and output escaping on user supplied attributes. Affected Versions:
WordPress LiteSpeed Cache before 5.7

QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for LiteSpeed Cache Plugin using Blind Elephant Fingerprint technique.

Successful exploitation of this vulnerability could allow an unauthenticated attackers to stealing sensitive information on the the target system.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to install LiteSpeed Cache 5.7 or later version to remediate this vulnerability.
    Vendor References

    CVEs related to QID 731249

    Software Advisories
    Advisory ID Software Component Link
    Litespeed-cache URL Logo wordpress.org/plugins/litespeed-cache/#developers