6.1
CVSSv3

CVE-2021-24964

Published: 03/01/2022 Updated: 08/01/2022
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

The LiteSpeed Cache WordPress plugin prior to 4.4.4 does not properly verify that requests are coming from QUIC.cloud servers, allowing malicious users to make requests to certain endpoints by using a specific X-Forwarded-For header value. In addition, one of the endpoint could be used to set CSS code if a setting is enabled, which will then be output in some pages without being sanitised and escaped. Combining those two issues, an unauthenticated attacker could put Cross-Site Scripting payloads in pages visited by users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

litespeedtech litespeed cache