{“error”:0,”message”:null,”data”:{“name”:”LiteSpeed Cache”,”plugin”:”litespeed-cache”,”link”:”https:\/\/wordpress.org\/plugins\/litespeed-cache\/”,”latest”:”1760712900″,”closed”:0,”vulnerability”:[{“uuid”:”4b0f12928658e93d3edc2c5b4f63d60cee2e202cb3e2210ca9d8cffef824b9b8″,”name”:”LiteSpeed Cache [litespeed-cache] < 4.4.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.4.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24963","name":"CVE-2021-24963","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24963","description":"[en] The LiteSpeed Cache WordPress plugin before 4.4.4 does not escape the qc_res parameter before outputting it back in the JS code of an admin page, leading to a Reflected Cross-Site Scripting","date":"2022-01-03"},{"id":"0c975c0b5745a76577ac336ace529262b2d3a5fb","name":"WordPress LiteSpeed Cache plugin <= 4.4.3 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/litespeed-cache\/vulnerability\/wordpress-litespeed-cache-plugin-4-4-3-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability discovered by Emil Kylander in WordPress LiteSpeed Cache plugin (versions <= 4.4.3).","date":"2021-11-30"},{"id":"0a82c9a7eb40288f049b68e287ebe205c4debff6","name":"LiteSpeed Cache <= 4.4.3 - Reflected Cross-Site Scripting via qc_res","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/litespeed-cache\/litespeed-cache-443-reflected-cross-site-scripting-via-qc-res","description":"The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'qc_res' parameter in versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2021-11-30"},{"id":"7f8b4275-7586-4e04-afd9-d12bdab6ba9b","name":"LiteSpeed Cache < 4.4.4 - Admin+ Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/7f8b4275-7586-4e04-afd9-d12bdab6ba9b","description":"The plugin does not escape the qc_res parameter before outputting it back in the JS code of an admin page, leading to a Reflected Cross-Site Scripting","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"85e19d7e7e5ca33030a64c11f162562576334f7d88fe0b16cacf8b5b1542ac78","name":"LiteSpeed Cache [litespeed-cache] < 4.4.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.4.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24964","name":"CVE-2021-24964","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24964","description":"[en] The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud servers, allowing attackers to make requests to certain endpoints by using a specific X-Forwarded-For header value. In addition, one of the endpoint could be used to set CSS code if a setting is enabled, which will then be output in some pages without being sanitised and escaped. Combining those two issues, an unauthenticated attacker could put Cross-Site Scripting payloads in pages visited by users.","date":"2022-01-03"},{"id":"213bb13c1c1ba5fd533afd8aab1a05ac1df7c2fd","name":"WordPress LiteSpeed Cache plugin <= 4.4.3 - IP Check Bypass to Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/litespeed-cache\/vulnerability\/wordpress-litespeed-cache-plugin-4-4-3-ip-check-bypass-to-unauthenticated-stored-cross-site-scripting-xss-vulnerability","description":"IP Check Bypass to Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Emil Kylander in WordPress LiteSpeed Cache plugin (versions <= 4.4.3).","date":"2021-11-30"},{"id":"b87c6381422e8b0c8ba73aaf137695dd231ac36d","name":"LiteSpeed Cache <= 4.4.3 - Authorization Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/litespeed-cache\/litespeed-cache-443-authorization-bypass","description":"The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud servers, allowing attackers to make requests to certain endpoints by using a specific X-Forwarded-For header value. In addition, one of the endpoint could be used to set CSS code if a setting is enabled, which will then be output in some pages without being sanitised and escaped. Combining those two issues, an unauthenticated attacker could put Cross-Site Scripting payloads in pages visited by users.","date":"2021-11-30"},{"id":"e9966b3e-2eb9-4d70-8c18-6a829b4827cc","name":"LiteSpeed Cache < 4.4.4 - IP Check Bypass to Unauthenticated Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/e9966b3e-2eb9-4d70-8c18-6a829b4827cc","description":"The plugin does not properly verify that requests are coming from QUIC.cloud servers, allowing attackers to make requests to certain endpoints by using a specific X-Forwarded-For header value. In addition, one of the endpoint could be used to set CSS code if a setting is enabled, which will then be output in some pages without being sanitised and escaped. Combining those two issues, an unauthenticated attacker could put Cross-Site Scripting payloads in pages visited by users.","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"b29db9cc8b2e066e4ac8d76ac5aaab86f17c3814eed23a8102385bdd6f827b09","name":"LiteSpeed Cache [litespeed-cache] < 3.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-29172","name":"CVE-2020-29172","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-29172","description":"[en] A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.","date":"2020-12-26"},{"id":"1dd9c953e680913ed8d595fd8a88ecc52dd4c0c8","name":"LiteSpeed Cache <= 3.6 - Authenticated Stored Cross-Site Scripting via IP setting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/litespeed-cache\/litespeed-cache-36-authenticated-stored-cross-site-scripting-via-ip-setting","description":"A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.","date":"2020-12-26"},{"id":"8ef35524-d996-4285-aca2-dc62e02c074d","name":"LiteSpeed Cache < 3.6.1 - Authenticated Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/8ef35524-d996-4285-aca2-dc62e02c074d","description":"The plugin does not sanitise invalid IPs given in its Toolbox page before displaying them in an error message.","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"462a6eeaf9ea5cd1b1896712df9944f86d2ccab017341c0813c61b2513a4077f","name":"LiteSpeed Cache [litespeed-cache] < 3.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a964939a3461eb6426467710989c66abeb050f0b","name":"WordPress LiteSpeed Cache plugin <= 3.6 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/litespeed-cache\/vulnerability\/wordpress-litespeed-cache-plugin-3-6-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by WonTae Jang in WordPress LiteSpeed Cache plugin (versions <= 3.6).","date":"2020-12-26"}],"impact":[]},{"uuid":"370009a2c78edafc6c31a4b18cf1a673c3b3d1d0fb33770a79f1ec3779989806","name":"LiteSpeed Cache [litespeed-cache] < 5.3.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.3.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-46800","name":"CVE-2022-46800","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-46800","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache plugin <=\u00a05.3 versions.","date":"2023-05-25"},{"id":"e5bfd4261aa74c4154955a10c691eec0b14809e7","name":"WordPress LiteSpeed Cache Plugin <= 5.3 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/litespeed-cache\/vulnerability\/wordpress-litespeed-cache-plugin-5-3-cross-site-request-forgery-csrf-vulnerability","description":"Update the WordPress LiteSpeed Cache plugin to the latest available version (at least 5.3.1).\nthiennv discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress LiteSpeed Cache Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 5.3.1.","date":"2023-03-22"},{"id":"e66e828e0f91534073a31b5d84fdafe380d7c56e","name":"LiteSpeed Cache <= 5.3 - Missing Authorization to Toggle Crawler State","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/litespeed-cache\/litespeed-cache-53-missing-authorization-to-toggle-crawler-state","description":"The LiteSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rest_api_init function in versions up to, and including, 5.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to activate or deactivate arbitrary crawlers.","date":"2023-03-22"},{"id":"210793a4-4f79-4f11-8290-adff79fc66c2","name":"LiteSpeed Cache <= 5.3 - CSRF","link":"https:\/\/wpscan.com\/vulnerability\/210793a4-4f79-4f11-8290-adff79fc66c2","description":"The plugin does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"39807600659618cce22dc36d19dffb27e534d851f1afb69ad402a5effec169e0","name":"LiteSpeed Cache [litespeed-cache] < 5.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-4372","name":"CVE-2023-4372","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-4372","description":"[en] The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in versions up to, and including, 5.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-01-11"},{"id":"2d473adf747a2a30c6fdf1a50b834029352543ec","name":"LiteSpeed Cache <= 5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/litespeed-cache\/litespeed-cache-56-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in versions up to, and including, 5.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-10-23"},{"id":"4ce716f2a5b87a28700e558bd20be0809202df72","name":"WordPress LiteSpeed Cache Plugin <= 5.6 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/litespeed-cache\/vulnerability\/wordpress-litespeed-cache-plugin-5-6-authenticated-contributor-stored-cross-site-scripting-via-shortcode-vulnerability","description":"Update the WordPress LiteSpeed Cache plugin to the latest available version (at least 5.7).\nLana Codes discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress LiteSpeed Cache Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 5.7.","date":"2023-10-26"},{"id":"df24c0e0-62b7-4a48-aaa5-afddbf917ce7","name":"LiteSpeed Cache < 5.7 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/df24c0e0-62b7-4a48-aaa5-afddbf917ce7","description":"The plugin does not escape the cache attribute of its esi shortcode before outputting it back in a page\/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"5fe3e0f065efa6c3110399c55deda0c8a0150961b11bb280c0bcb23f43c7334d","name":"LiteSpeed Cache [litespeed-cache] < 5.7.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.7.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-45000","name":"CVE-2023-45000","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-45000","description":"[en] Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cache: from n\/a through 5.7.","date":"2024-04-16"},{"id":"24f31f90db814f928c7d2da2e0b2ff7400209ff9","name":"WordPress LiteSpeed Cache Plugin <= 5.7 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/litespeed-cache\/vulnerability\/wordpress-litespeed-cache-plugin-5-7-unauthenticated-broken-access-control-on-api-vulnerability","description":"Update the WordPress LiteSpeed Cache plugin to the latest available version (at least 5.7.0.1).\nRafie Muhammad (Patchstack) discovered and reported this Broken Access Control vulnerability in WordPress LiteSpeed Cache Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 5.7.0.1.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"54ef918b1378c2b81b4d4c735c9bb5b0d42b6c77","name":"LiteSpeed Cache <= 5.7 - Missing Authorization via update_cdn_status","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/litespeed-cache\/litespeed-cache-57-missing-authorization-via-update-cdn-status","description":"The LiteSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the 'update_cdn_status' function in versions up to, and including, 5.7. This makes it possible for unauthenticated attackers to modify the plugin's CDN status.","date":"2024-02-27"},{"id":"a269a9a7-909b-46ef-b2b8-fc5cae02d57a","name":"LiteSpeed Cache < 5.7.0.1 - Unauthenticated CDN Status Update","link":"https:\/\/wpscan.com\/vulnerability\/a269a9a7-909b-46ef-b2b8-fc5cae02d57a","description":"The plugin is vulnerable to unauthorized modification of data due to a missing authorization check on the 'update_cdn_status' function, allowing unauthenticated attackers to modify the plugin's CDN status.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"l","a":"n","score":"8.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}]}},{"uuid":"f8a5161f4743a6c3fd256b8856bb5912d9c85786164675a9cc83a402aa60a557","name":"LiteSpeed Cache [litespeed-cache] < 5.7.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.7.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-40000","name":"CVE-2023-40000","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-40000","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n\/a through 5.7.","date":"2024-04-16"},{"id":"38fc2fd867148f97bde241b2fd4d78170f4356e2","name":"WordPress LiteSpeed Cache Plugin <= 5.7 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/litespeed-cache\/vulnerability\/wordpress-litespeed-cache-plugin-5-7-unauthenticated-site-wide-stored-xss-vulnerability","description":"Update the WordPress LiteSpeed Cache plugin to the latest available version (at least 5.7.0.1).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress LiteSpeed Cache Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 5.7.0.1.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"29359746bc7a5c86d39b57c30dcf37e56f7cd352","name":"LiteSpeed Cache <= 5.7 - Unauthenticated Stored Cross-Site Scripting via 'nameservers' and '_msg'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/litespeed-cache\/litespeed-cache-57-reflected-cross-site-scripting-via-nameservers-and-msg","description":"The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nameservers' and '_msg' parameters in all versions up to, and including, 5.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-02-27"},{"id":"dd9054cc-1259-427d-a4ad-1875b7b2b3b4","name":"LiteSpeed Cache < 5.7.0.1 - Unauthenticated Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/dd9054cc-1259-427d-a4ad-1875b7b2b3b4","description":"The plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nameservers' and '_msg' parameters due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"l","score":"8.3","severity":"h","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"713e4660828d7fb6f073e026e5d6dfc044da7fc0c3efa34c0bfdf5e24dbeaba8","name":"LiteSpeed Cache [litespeed-cache] < 6.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3246","name":"CVE-2024-3246","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3246","description":"[en] The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to update the token setting and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-07-24"},{"id":"8542efafb1e1cdf3236c49f9f9d1586b10b34bfc","name":"WordPress LiteSpeed Cache Plugin <= 6.2.0.1 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/litespeed-cache\/vulnerability\/wordpress-litespeed-cache-plugin-6-2-0-1-cross-site-request-forgery-csrf-on-quick-cloud-token-update-vulnerability","description":"
WordPress LiteSpeed Cache Plugin <= 6.2.0.1 is vulnerable to Cross Site Request Forgery (CSRF)<\/p>
Software: LiteSpeed Cache<\/p>
Link: https:\/\/wordpress.org\/plugins\/litespeed-cache\/#developers<\/p>
Affected Version <= 6.2.0.1<\/p>
Fixed in version 6.3 <\/p>“,”date”:”2024-07-23″},{“id”:”af818a75f67af266dfb9236f5f2dadd6085aefb4″,”name”:”LiteSpeed Cache <= 6.2.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/litespeed-cache\/litespeed-cache-6201-cross-site-request-forgery-to-stored-cross-site-scripting","description":"The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to update the token setting and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-07-23"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"81a902c2ff922ec5a11ff27e7ec89ce3d1fcb30f3f18d9d82932351e942482f4","name":"LiteSpeed Cache [litespeed-cache] < 6.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-28000","name":"CVE-2024-28000","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-28000","description":"[en] Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from 1.9 through 6.3.0.1.","date":"2024-08-21"},{"id":"5c64f41c6fb8c7abbf20d8010f685f123cc15adb","name":"WordPress LiteSpeed Cache Plugin <= 6.3.0.1 is vulnerable to Privilege Escalation","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/litespeed-cache\/vulnerability\/wordpress-litespeed-cache-plugin-6-3-0-1-unauthenticated-privilege-escalation-vulnerability","description":"
WordPress LiteSpeed Cache Plugin <= 6.3.0.1 is vulnerable to Privilege Escalation<\/p>
Software: LiteSpeed Cache<\/p>
Link: https:\/\/wordpress.org\/plugins\/litespeed-cache\/#developers<\/p>
Affected Version <= 6.3.0.1<\/p>
Fixed in version 6.4 <\/p>“,”date”:”2024-08-19″},{“id”:”464fba730dfbe5828efc0ff92cdbca24fd770772″,”name”:”LiteSpeed Cache <= 6.3.0.1 - Unauthenticated Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/litespeed-cache\/litespeed-cache-6301-unauthenticated-privilege-escalation","description":"The LiteSpeed Cache plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.3.0.1. This is due to the plugin not properly restricting the role simulation functionality allowing a user to set their current ID to that of an administrator, if they have access to a valid hash which can be found in the debug logs or brute forced. This makes it possible for unauthenticated attackers to spoof their user ID to that of an administrator, and then create a new user account with the administrator role utilizing the \/wp-json\/wp\/v2\/users REST API endpoint. In some environments, the crawler may be disabled making this a non-exploitable issue in those instances.","date":"2024-08-21"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-266","name":"Incorrect Privilege Assignment","description":"A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor."}]}},{"uuid":"5e9fd9232680db33f74c3ad4845debcd0e8b3ad87350205e8dd69b2e8bce7add","name":"LiteSpeed Cache [litespeed-cache] < 6.5.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-44000","name":"CVE-2024-44000","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-44000","description":"[en] Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n\/a before 6.5.0.1.","date":"2024-10-20"},{"id":"84276f970126c25a77f6513ba4103eb3cd92e312","name":"WordPress LiteSpeed Cache Plugin < 6.5.0.1 is vulnerable to Broken Authentication","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/litespeed-cache\/vulnerability\/wordpress-litespeed-cache-plugin-6-5-0-1-unauthenticated-account-takeover-vulnerability","description":"
WordPress LiteSpeed Cache Plugin < 6.5.0.1 is vulnerable to Broken Authentication<\/p>
Software: LiteSpeed Cache<\/p>
Link: https:\/\/wordpress.org\/plugins\/litespeed-cache\/#developers<\/p>
Affected Version < 6.5.0.1<\/p>
Fixed in version 6.5.0.1 <\/p>“,”date”:”2024-09-05″},{“id”:”a1899235e00b6384952bb1cbff4700d76d5d10a5″,”name”:”LiteSpeed Cache <= 6.4.1 - Unauthenticated Sensitive Information Exposure via Log Files","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/litespeed-cache\/litespeed-cache-641-unauthenticated-sensitive-information-exposure-via-log-files","description":"The LiteSpeed Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.4.1 through the debug.log file that is publicly exposed. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log file. The log file may contain user cookies making it possible for an attacker to log in with any session that is actively valid and exposed in the log file. Note: the debug feature must be enabled for this to be a concern and this feature is disabled by default.","date":"2024-09-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-522","name":"Insufficiently Protected Credentials","description":"The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and\/or retrieval."}]}},{"uuid":"efd9564e2ed72e157a09f6313c0cfc0f91ad3a9ee1103efcd7326a6e090ca624","name":"LiteSpeed Cache [litespeed-cache] < 6.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-9169","name":"CVE-2024-9169","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-9169","description":"[en] The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up to, and including, 6.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-09-25"},{"id":"1befd089942e68d482c5907ed3189e02568b0606","name":"WordPress LiteSpeed Cache Plugin <= 6.4.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/litespeed-cache\/vulnerability\/wordpress-litespeed-cache-plugin-6-4-1-authenticated-administrator-stored-cross-site-scripting-vulnerability","description":"
WordPress LiteSpeed Cache Plugin <= 6.4.1 is vulnerable to Cross Site Scripting (XSS)<\/p>
Software: LiteSpeed Cache<\/p>
Link: https:\/\/wordpress.org\/plugins\/litespeed-cache\/#developers<\/p>
Affected Version <= 6.4.1<\/p>
Fixed in version 6.5 <\/p>“,”date”:”2024-09-25″},{“id”:”78de5ecf98ad52a4dca3f65938856462de69ad16″,”name”:”litespeed cache <= 6.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/litespeed-cache\/litespeed-cache-641-authenticated-administrator-stored-cross-site-scripting","description":"The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up to, and including, 6.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-09-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"5.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"46312120dce9c30c3e612d89bd4dba31e52e4362982183fec96ffe409585de0c","name":"LiteSpeed Cache [litespeed-cache] < 6.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-47637","name":"CVE-2024-47637","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-47637","description":"[en] : Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Path Traversal.This issue affects LiteSpeed Cache: from n\/a through 6.4.1.","date":"2024-10-16"},{"id":"52ed3cae7821c632eda64de48063813e46eb5c30","name":"WordPress LiteSpeed Cache Plugin <= 6.4.1 is vulnerable to Path Traversal","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/litespeed-cache\/vulnerability\/wordpress-litespeed-cache-plugin-6-4-1-path-traversal-vulnerability","description":"
WordPress LiteSpeed Cache Plugin <= 6.4.1 is vulnerable to Path Traversal<\/p>
Software: LiteSpeed Cache<\/p>
Link: https:\/\/wordpress.org\/plugins\/litespeed-cache\/#developers<\/p>
Affected Version <= 6.4.1<\/p>
Fixed in version 6.5.1 <\/p>“,”date”:”2024-09-30″},{“id”:”41167a697582b2d52b55752fb6bd12ae7ea0b144″,”name”:”LiteSpeed Cache <= 6.4.1 - Authenticated (Author+) Path Traversal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/litespeed-cache\/litespeed-cache-641-authenticated-author-path-traversal","description":"The LiteSpeed Cache plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.4.1. This makes it possible for authenticated attackers, with author-level access and above, to perform actions on files outside of the originally intended directory.","date":"2024-09-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-23","name":"Relative Path Traversal","description":"The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as \"..\" that can resolve to a location that is outside of that directory."}]}},{"uuid":"a210041807a3e8be1bffa21ee71d0f356b6738d680d33bce5e7408076f743079","name":"LiteSpeed Cache [litespeed-cache] < 6.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-47374","name":"CVE-2024-47374","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-47374","description":"[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n\/a through 6.5.0.2.","date":"2024-10-05"},{"id":"d7fed3d5eaec9c9737222e76f1e07602d55c4c59","name":"WordPress LiteSpeed Cache Plugin <= 6.5.0.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/litespeed-cache\/vulnerability\/wordpress-litespeed-cache-plugin-6-5-0-2-cross-site-scripting-xss-vulnerability","description":"
WordPress LiteSpeed Cache Plugin <= 6.5.0.2 is vulnerable to Cross Site Scripting (XSS)<\/p>
Software: LiteSpeed Cache<\/p>
Link: https:\/\/wordpress.org\/plugins\/litespeed-cache\/#developers<\/p>
Affected Version <= 6.5.0.2<\/p>
Fixed in version 6.5.1 <\/p>“,”date”:”2024-09-30″},{“id”:”80eae689514b6cf20ad269093e206ac566b4eb10″,”name”:”LiteSpeed Cache <= 6.1 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/litespeed-cache\/litespeed-cache-61-unauthenticated-stored-cross-site-scripting","description":"The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-LSCACHE-VARY-VALUE' header in all versions up to, and including, 6.5.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the CSS Combine and Generate UCSS settings to be enabled.","date":"2024-09-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"4c9dd968895ed8edb169bffe120bcf95d9688ef47218b5ae30cd825aa9e27fc7","name":"LiteSpeed Cache [litespeed-cache] < 6.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-47373","name":"CVE-2024-47373","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-47373","description":"[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n\/a through 6.5.0.2.","date":"2024-10-05"},{"id":"959498fd970118e50b9d0523fd4866175514b8ef","name":"WordPress LiteSpeed Cache Plugin <= 6.5.0.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/litespeed-cache\/vulnerability\/wordpress-litespeed-cache-plugin-6-5-0-2-cross-site-scripting-xss-vulnerability-2","description":"
WordPress LiteSpeed Cache Plugin <= 6.5.0.2 is vulnerable to Cross Site Scripting (XSS)<\/p>
Software: LiteSpeed Cache<\/p>
Link: https:\/\/wordpress.org\/plugins\/litespeed-cache\/#developers<\/p>
Affected Version <= 6.5.0.2<\/p>
Fixed in version 6.5.1 <\/p>“,”date”:”2024-09-30″},{“id”:”9165f5720095379b2849e073d2569f89b474a485″,”name”:”LiteSpeed Cache <= 6.5.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/litespeed-cache\/litespeed-cache-6502-authenticated-contributor-stored-cross-site-scripting","description":"The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.5.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-09-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"448bf7b968220042c47eedad98062617b17a05cd2c8337a4d748fdbbe2e5e8c1","name":"LiteSpeed Cache [litespeed-cache] < 6.5.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-50550","name":"CVE-2024-50550","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-50550","description":"[en] Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n\/a through 6.5.1.","date":"2024-10-29"},{"id":"28e3bbc9e33097d26f3cc18ad317c7e9a07c70d0","name":"WordPress LiteSpeed Cache Plugin <= 6.5.1 is vulnerable to Privilege Escalation","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/litespeed-cache\/vulnerability\/wordpress-litespeed-cache-plugin-6-5-1-privilege-escalation-vulnerability","description":"
WordPress LiteSpeed Cache Plugin <= 6.5.1 is vulnerable to Privilege Escalation<\/p>
Software: LiteSpeed Cache<\/p>
Link: https:\/\/wordpress.org\/plugins\/litespeed-cache\/#developers<\/p>
Affected Version <= 6.5.1<\/p>
Fixed in version 6.5.2 <\/p>“,”date”:”2024-10-29″},{“id”:”d21eb98ca9000cc76cfc61897bbb9bd23d0852f3″,”name”:”LiteSpeed Cache <= 6.5.1 - Unauthenticated Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/litespeed-cache\/litespeed-cache-651-unauthenticated-privilege-escalation","description":"The LiteSpeed Cache plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.1. This is due to the is_role_simulation() function not properly providing protection against unauthorized use of the function. This makes it possible for unauthenticated attackers to simulate roles such as administrators which provides elevated access to the site. Please note there are a lot of pre-requisites for this to be exploitable.","date":"2024-10-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-266","name":"Incorrect Privilege Assignment","description":"A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor."}]}},{"uuid":"1a77805000ec857632648d3c290d6e4da0f284be74f3c4955f8e14f9c4c96571","name":"LiteSpeed Cache [litespeed-cache] < 6.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-51915","name":"CVE-2024-51915","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-51915","description":"","date":null},{"id":"4019080b5d6896371b9535ba6d9a023720105e74","name":"WordPress LiteSpeed Cache Plugin <= 6.5.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/litespeed-cache\/vulnerability\/wordpress-litespeed-cache-plugin-6-5-2-cross-site-scripting-xss-vulnerability","description":"
WordPress LiteSpeed Cache Plugin <= 6.5.2 is vulnerable to Cross Site Scripting (XSS)<\/p>
Software: LiteSpeed Cache<\/p>
Fixed in version 6.5.3 <\/p>
Affected Version <= 6.5.2<\/p>
CVE: CVE-2024-51915<\/p>“,”date”:”2024-12-20″}],”impact”:[]},{“uuid”:”6aa0183de0170f9cb0674ad43b2dc05104eb60b5fcb05dff91f7ae39a2648ee9″,”name”:”LiteSpeed Cache [litespeed-cache] < 7.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-47437","name":"CVE-2025-47437","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-47437","description":"[en] Server-Side Request Forgery (SSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache. This issue affects LiteSpeed Cache: from n\/a through 7.0.1.","date":"2025-09-09"},{"id":"3f40a3003f8e08000d3b500b50f26659ed161087","name":"LiteSpeed Cache <= 7.0.1 - Authenticated (Editor+) Server-Side Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/litespeed-cache\/litespeed-cache-701-authenticated-editor-server-side-request-forgery","description":"The LiteSpeed Cache plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.1. This makes it possible for authenticated attackers, with Editor-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-918","name":"Server-Side Request Forgery (SSRF)","description":"The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination."}]}},{"uuid":"5a495657b534a8169c736056313cc819ac587811d1512279bb473d05ee04b6f4","name":"LiteSpeed Cache [litespeed-cache] < 7.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-12450","name":"CVE-2025-12450","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-12450","description":"[en] The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 7.5.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2025-10-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}}]},"updated":"1761804462"}