NA

CVE-2023-40000

Published: 16/04/2024 Updated: 17/04/2024

Vulnerability Summary

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a up to and including 5.7.

Vulnerability Trend

Vendor Advisories

Check Point Reference: CPAI-2023-1568 Date Published: 7 Mar 2024 Severity: High ...

Github Repositories

A list of all of my starred repos, automated using Github Actions 🌟

awesome stars A list of awesome repositories I've starred Want your own? Try: stargazer Total starred repositories: 272 Contents Astro Batchfile C C# C++ CSS Dart Dockerfile Elixir Go HCL HTML Java JavaScript PHP PowerShell Python Ruby Rust Sass Scala Shell Swift TypeScript Unknown Vue Astro Lissy93/awesome-privacy - πŸ¦„ A curated list of privacy & security-f

A list of all of my starred repos, automated using Github Actions 🌟

awesome stars A list of awesome repositories I've starred Want your own? Try: stargazer Total starred repositories: 272 Contents Astro Batchfile C C# C++ CSS Dart Dockerfile Elixir Go HCL HTML Java JavaScript PHP PowerShell Python Ruby Rust Sass Scala Shell Swift TypeScript Unknown Vue Astro Lissy93/awesome-privacy - πŸ¦„ A curated list of privacy & security-f

LiteSpeed Cache plugin for WordPress that could enable unauthenticated users to escalate their privileges

CVE-2023-40000 LiteSpeed Cache plugin for WordPress that could enable unauthenticated users to escalate their privileges How does this detection method work? This template looks at the following path: /wp-content/plugins/litespeed-cache/readmetxt Based on the Stable Tag listed, if the version is prior to 5701 then it is considered to be vulnerable How do I run this templat

PoC for XSS vulnerability in the LiteSpeed Cache WordPress plugin (CVE-2023-40000) allowing elevated privileges. Includes code, explanations, and mitigations.

LiteSpeed Cache XSS PoC PoC for XSS vulnerability in the LiteSpeed Cache WordPress plugin allowing elevated privileges This vulnerability was fixed in version 5701 of the plugin, and was assigned CVE-2023-40000 According to the plugin's advanced view page, about 35% of users are still using a vulnerable version (<5701), which adds up to about 18M websites

That's a PoC of cve-2023-40000. Wordpress LiteSpeed Cache exploit.

cve-2023-40000 That's a PoC of cve-2023-40000 Wordpress LiteSpeed Cache exploit

Recent Articles

Hackers exploit LiteSpeed Cache flaw to create WordPress admins
BleepingComputer β€’ Bill Toulas β€’ 07 May 2024

Hackers exploit LiteSpeed Cache flaw to create WordPress admins By Bill Toulas May 7, 2024 05:42 PM 0 Hackers have been targeting WordPress sites with an outdated version of the LiteSpeed Cache plugin to create administrator users and gain control of the websites. LiteSpeed Cache (LS Cache) is advertised as a caching plugin used in over five million WordPress sites that helps speed up page loads, improve visitor experience, and boost Google Search ranking. Automattic's security te...