logo

WordPress LiteSpeed Plugin Vulnerability Puts 5 Million Sites at Risk

ID: d4e698ce-4a68-5d5f-aee7-5ee961beb80d

STIX ID: report--d4e698ce-4a68-5d5f-aee7-5ee961beb80d

Feed Name: The Hacker News

Threat Score
60/100

Date Published: 2024-02-27

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A stored cross-site scripting vulnerability (CVE-2023-40000) in the LiteSpeed Cache WordPress plugin can allow unauthenticated users to inject admin notices and achieve privilege escalation or data theft; the issue is due to missing input sanitization/escaping in update_cdn_status() and was fixed in version 5.7.0.1 (Oct 2023). The plugin has over five million installations, increasing potential exposure, though the report does not provide evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.