CVE-2024-51915: WordPress LiteSpeed Cache plugin <= 6.5.2 - Cross Site Scripting (XSS) vulnerability
Published Feb 20, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through <= 6.5.2.
Affected Software
2 affected components
Litespeed Technologies LiteSpeed Cache>n/a, <=6.5.2
wordpress/litespeed-cache<=6.5.2
Event History
Feb 20, 2026
CVE Published
via MITRE·03:46 PM
Data Sourced
via MITRE·03:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-51915?
The severity of CVE-2024-51915 is classified as medium with a CVSS score of 6.5.
2
What vulnerability does CVE-2024-51915 expose in the LiteSpeed Cache plugin?
CVE-2024-51915 exposes a Cross Site Scripting (XSS) vulnerability due to improper neutralization of input.
3
How do I fix CVE-2024-51915?
To fix CVE-2024-51915, upgrade the LiteSpeed Cache plugin to version 6.5.3 or later.
4
Which versions of the LiteSpeed Cache plugin are affected by CVE-2024-51915?
CVE-2024-51915 affects LiteSpeed Cache versions from n/a through 6.5.2.
5
What is stored XSS as mentioned in CVE-2024-51915?
Stored XSS in CVE-2024-51915 allows attackers to inject malicious scripts that can be executed upon user interaction.