CVE-2023-40000: WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability
Published Apr 16, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.
Affected Software
3 affected components
Litespeed Technologies LiteSpeed Cache>=n/a, <=5.7
WordPress LiteSpeed Cache<=5.7
Litespeedtech Litespeed Cache Wordpress<5.7.0.1
Remediation
Information
Update to 5.7.0.1 or a higher version.
Event History
Apr 16, 2024
CVE Published
via MITRE·05:46 PM
Data Sourced
via MITRE·05:46 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
May 7, 2024
News Published
via BleepingComputer·09:42 PM
News Published
via BleepingComputer·09:44 PM
Aug 21, 2024
News Published
via BleepingComputer·05:22 PM
Aug 22, 2024
News Published
via BleepingComputer·10:14 PM
Sep 5, 2024
News Published
via BleepingComputer·04:58 PM
Oct 31, 2024
News Published
via BleepingComputer·04:19 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-40000?
CVE-2023-40000 is categorized as a Stored XSS vulnerability with significant risk to affected systems.
2
How do I fix CVE-2023-40000?
To fix CVE-2023-40000, update LiteSpeed Cache to version 5.8 or later, which addresses the XSS issues.
3
Which versions are affected by CVE-2023-40000?
CVE-2023-40000 affects LiteSpeed Cache versions from n/a up to and including 5.7.
4
What types of attacks are possible due to CVE-2023-40000?
CVE-2023-40000 could allow attackers to execute scripts in the context of a user's browser, potentially compromising sensitive data.
5
Is WordPress LiteSpeed Cache impacted by CVE-2023-40000?
Yes, the WordPress LiteSpeed Cache plugin up to version 5.7 is also vulnerable to CVE-2023-40000.