CVE-2023-45000: WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Broken Access Control on API vulnerability
Published Apr 16, 2024
·Updated
Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cache: from n/a through 5.7.
Affected Software
3 affected components
Litespeed Technologies LiteSpeed Cache<=5.7
WordPress LiteSpeed Cache plugin<=5.7
Litespeedtech Litespeed Cache Wordpress<5.7.0.1
Remediation
Information
Update to 5.7.0.1 or a higher version.
Event History
Apr 16, 2024
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-45000?
CVE-2023-45000 is classified as a Missing Authorization vulnerability, indicating a high risk for unauthorized access.
2
How do I fix CVE-2023-45000?
To fix CVE-2023-45000, upgrade LiteSpeed Cache to version 5.8 or later to mitigate the vulnerability.
3
What products are affected by CVE-2023-45000?
CVE-2023-45000 affects LiteSpeed Cache versions up to 5.7 and the WordPress LiteSpeed Cache plugin versions up to 5.7.
4
Does CVE-2023-45000 affect all LiteSpeed Cache versions?
No, only LiteSpeed Cache versions prior to 5.8 are affected by CVE-2023-45000.
5
Is CVE-2023-45000 a known vulnerability?
Yes, CVE-2023-45000 is a publicly reported vulnerability that has been documented in various cybersecurity databases.