CVE-2020-29172: XSS
Published Dec 26, 2020
·Updated
A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.
Affected Software
1 affected component
Litespeedtech Litespeed Cache Wordpress<3.6.1
Event History
Dec 26, 2020
CVE Published
via MITRE·01:56 AM
Data Sourced
via MITRE·01:56 AM
Description
Frequently Asked Questions
1
What is CVE-2020-29172?
CVE-2020-29172 is a cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before version 3.6.1 for WordPress.
2
How can CVE-2020-29172 be exploited?
CVE-2020-29172 can be exploited through the Server IP setting in the LiteSpeed Cache plugin.
3
What is the severity of CVE-2020-29172?
CVE-2020-29172 has a severity rating of 6.1 (medium).
4
Which versions of the LiteSpeed Cache plugin for WordPress are affected by CVE-2020-29172?
Versions of the LiteSpeed Cache plugin before 3.6.1 for WordPress are affected by CVE-2020-29172.
5
How can I fix CVE-2020-29172?
To fix CVE-2020-29172, update the LiteSpeed Cache plugin to version 3.6.1 or later.