Single HTTP Request Can Exploit 6M WordPress Sites
ID: 7d2eedc4-97aa-5851-bfc4-15d12deeb285
STIX ID: report--7d2eedc4-97aa-5851-bfc4-15d12deeb285
Feed Name: Dark Reading
Date Published: 2024-10-07
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
A critical unauthenticated stored XSS vulnerability (CVE-2024-47374) was discovered in the LiteSpeed Cache WordPress plugin (affecting versions through 6.5.0.2) that can enable privilege escalation and injection of malicious HTML on sites using the plugin; Patchstack and the plugin developer released fixes (v6.5.1) and mitigation guidance, and administrators are advised to update immediately due to the plugin's large install base.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
