Vulnerability record · CVE-2023-40000 · published 16 April 2024
CVE-2023-40000: LiteSpeed Cache unauthenticated stored XSS via web page generation
Litespeedtech · Litespeed Cache
LiteSpeed Cache, a WordPress plugin, fails to neutralize input during web page generation, allowing stored cross-site scripting in versions up to and including 5.7. Because the payload is stored and served to other visitors, a single injection can affect many users of the site. The CVSS score is 6.1 (medium) with a scope change, reflecting that the injected script runs in the context of the affected site.
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityUnauthenticated stored XSS with a public exploit and very high EPSS probability, though it requires user interaction and is rated medium by CVSS.
What it is
LiteSpeed Cache, a WordPress plugin, fails to neutralize input during web page generation, allowing stored cross-site scripting in versions up to and including 5.7. Because the payload is stored and served to other visitors, a single injection can affect many users of the site. The CVSS score is 6.1 (medium) with a scope change, reflecting that the injected script runs in the context of the affected site.
Impact
An attacker can run arbitrary script in the browsers of site visitors and logged-in users, enabling session theft, credential harvesting, or actions performed as the victim. The scope change means the compromise can extend beyond the vulnerable component to the surrounding site.
Attack surface
The vulnerability is network reachable and, per the reference title, unauthenticated, but the CVSS vector requires user interaction (UI:R), meaning a victim must view the page containing the stored payload. No privileges are needed to inject.
Exploitation
Not listed in CISA KEV, but a public exploit reference exists on GitHub and EPSS is high at 0.549 (99th percentile), indicating elevated likelihood of exploitation.
What to do
- Update LiteSpeed Cache to a version later than 5.7 as soon as possible.
- If immediate patching is not possible, disable or remove the plugin until it can be updated.
- Deploy a web application firewall rule to block stored XSS payloads targeting the plugin.
- Audit and clean stored content and cache entries that may contain injected scripts.
- Restrict untrusted content submission and review caching behavior for user-supplied data.
Detection
- Search web server and application logs for requests containing script tags or encoded script payloads to LiteSpeed Cache endpoints.
- Monitor for unexpected JavaScript in cached pages or stored content served to visitors.
- Review plugin and WordPress audit logs for content modifications by unauthenticated or low-privilege users.
- Use browser or endpoint telemetry to detect script execution originating from cached page content.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-40000 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-40000), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.