WordPress LiteSpeed Plugin Vulnerability Puts 5 Million Sites at Risk
ID: d4e698ce-4a68-5d5f-aee7-5ee961beb80d
STIX ID: report--d4e698ce-4a68-5d5f-aee7-5ee961beb80d
Feed Name: The Hacker News
Threat Score
A stored cross-site scripting vulnerability (CVE-2023-40000) in the LiteSpeed Cache WordPress plugin can allow unauthenticated users to inject admin notices and achieve privilege escalation or data theft; the issue is due to missing input sanitization/escaping in update_cdn_status() and was fixed in version 5.7.0.1 (Oct 2023). The plugin has over five million installations, increasing potential exposure, though the report does not provide evidence of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
