CVE-2023-40000

WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability

Basic Information

CVE State
PUBLISHED
Reserved Date
August 08, 2023
Published Date
April 16, 2024
Last Updated
August 02, 2024
Vendor
LiteSpeed Technologies
Product
LiteSpeed Cache
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.
Tags
wordpress malware xtw nessus_scanner

CVSS Scores

CVSS v3.1

8.3 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

EPSS Score

Score
42.12% (Percentile: 97.26%) as of 2025-06-14

SSVC Information

Exploitation
poc
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (2025-04-02 00:00:00 UTC) Source
Used in Malware
Yes (added 2024-04-02 00:00:00 UTC) (xtw) Source

Known Exploited Vulnerability Information

Source Added Date
WPScan 2025-05-27 00:00:00 UTC

Scanner Integrations

Scanner URL Date Detected
Nessus https://www.tenable.com/plugins/nessus/206970 2024-09-11 12:37:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

rxerium/CVE-2023-40000

Type: github • Created: 2024-02-28 19:36:40 UTC • Stars: 6

LiteSpeed Cache plugin for WordPress that could enable unauthenticated users to escalate their privileges

Timeline

  • CVE ID Reserved

  • Used in xtw Malware

  • CVE Published to Public

  • Detected by Nessus

  • Added to KEVIntel