CVE-2023-40000

PUBLISHED

WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability

LiteSpeed Technologies · LiteSpeed Cache
PoC available

Recommended Action

Track for updates. Assess relevance to your asset inventory and enrichment workflows.

Confidence
Exploitation Status
PoC available
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
CVSS / EPSS
8.3 High

At a Glance

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.

CVE Published
Apr 16, 2024
CVSS
8.3 High
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
litespeed_technologies
litespeed_cache

0 to <= 5.7

Affected
LiteSpeed Technologies
LiteSpeed Cache

litespeed-cache

n/a to <= 5.7

Changed to unaffected at 5.7.0.1

Affected

CVE References

Recommended Actions

  • Track for updates. Assess relevance to your asset inventory and enrichment workflows.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.