CVE-2021-24963: LiteSpeed Cache < 4.4.4 - Admin+ Reflected Cross-Site Scripting
Published Jan 3, 2022
·Updated
The LiteSpeed Cache WordPress plugin before 4.4.4 does not escape the qcres parameter before outputting it back in the JS code of an admin page, leading to a Reflected Cross-Site Scripting
Affected Software
1 affected component
Litespeedtech Litespeed Cache Wordpress<4.4.4
Remediation
Patch Available
Event History
Jan 3, 2022
CVE Published
via MITRE·12:49 PM
Data Sourced
via MITRE·12:49 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this LiteSpeed Cache WordPress plugin vulnerability?
The vulnerability ID for this LiteSpeed Cache WordPress plugin vulnerability is CVE-2021-24963.
2
What is the description of CVE-2021-24963?
CVE-2021-24963 is a vulnerability in the LiteSpeed Cache WordPress plugin before version 4.4.4 that leads to a Reflected Cross-Site Scripting (XSS) attack.
3
How severe is CVE-2021-24963?
CVE-2021-24963 has a severity score of 4.8, which is considered medium severity.
4
Which version of the LiteSpeed Cache WordPress plugin is affected by CVE-2021-24963?
The LiteSpeed Cache WordPress plugin versions up to (but not including) 4.4.4 are affected by CVE-2021-24963.
5
How can I fix CVE-2021-24963?
To fix CVE-2021-24963, you should update the LiteSpeed Cache WordPress plugin to version 4.4.4 or higher.