← Vulnerability feed

Vulnerability record · CVE-2023-40000 · published 16 April 2024

CVE-2023-40000: LiteSpeed Cache unauthenticated stored XSS via web page generation

Litespeedtech · Litespeed Cache

LiteSpeed Cache, a WordPress plugin, fails to neutralize input during web page generation, allowing stored cross-site scripting in versions up to and including 5.7. Because the payload is stored and served to other visitors, a single injection can affect many users of the site. The CVSS score is 6.1 (medium) with a scope change, reflecting that the injected script runs in the context of the affected site.

6.1 CVSS 3.1 Medium EPSS 55% · top 1.0% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated stored XSS with a public exploit and very high EPSS probability, though it requires user interaction and is rated medium by CVSS.

What it is

LiteSpeed Cache, a WordPress plugin, fails to neutralize input during web page generation, allowing stored cross-site scripting in versions up to and including 5.7. Because the payload is stored and served to other visitors, a single injection can affect many users of the site. The CVSS score is 6.1 (medium) with a scope change, reflecting that the injected script runs in the context of the affected site.

Impact

An attacker can run arbitrary script in the browsers of site visitors and logged-in users, enabling session theft, credential harvesting, or actions performed as the victim. The scope change means the compromise can extend beyond the vulnerable component to the surrounding site.

Attack surface

The vulnerability is network reachable and, per the reference title, unauthenticated, but the CVSS vector requires user interaction (UI:R), meaning a victim must view the page containing the stored payload. No privileges are needed to inject.

Exploitation

Not listed in CISA KEV, but a public exploit reference exists on GitHub and EPSS is high at 0.549 (99th percentile), indicating elevated likelihood of exploitation.

What to do

  • Update LiteSpeed Cache to a version later than 5.7 as soon as possible.
  • If immediate patching is not possible, disable or remove the plugin until it can be updated.
  • Deploy a web application firewall rule to block stored XSS payloads targeting the plugin.
  • Audit and clean stored content and cache entries that may contain injected scripts.
  • Restrict untrusted content submission and review caching behavior for user-supplied data.

Detection

  • Search web server and application logs for requests containing script tags or encoded script payloads to LiteSpeed Cache endpoints.
  • Monitor for unexpected JavaScript in cached pages or stored content served to visitors.
  • Review plugin and WordPress audit logs for content modifications by unauthenticated or low-privilege users.
  • Use browser or endpoint telemetry to detect script execution originating from cached page content.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-40000 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-50550Litespeedtech litespeed cache inadequate encryption strength vulnerabilityIncorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects…EPSS 0.90%9.8CVE-2024-44000LiteSpeed Cache WordPress plugin authentication bypass via exposed credentialsLiteSpeed Cache versions before 6.5.0.1 contain an insufficiently protected credentials flaw (CWE-522) that allows authentication bypass. The referen…EPSS 82%analysed9.8CVE-2024-28000LiteSpeed Cache unauthenticated privilege escalation via weak hashLiteSpeed Cache for WordPress, up to version 6.3.0.1, assigns privileges incorrectly (CWE-266), allowing an unauthenticated attacker to escalate to a…EPSS 68%analysed8.8CVE-2024-47637Litespeedtech litespeed cache relative path traversal vulnerabilityRelative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Ca…EPSS 0.65%8.8CVE-2022-46800Litespeedtech litespeed cache cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache plugin <= 5.3 versions.EPSS 0.26%6.1CVE-2024-47374Litespeedtech litespeed cache cross-site scripting vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespee…EPSS 1.4%6.1CVE-2021-24964Litespeedtech litespeed cache cross-site scripting vulnerabilityThe LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud servers, allowing attackers to ma…EPSS 1.2%6.1CVE-2020-29172Litespeedtech litespeed cache cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.EPSS 0.94%

Source: NIST National Vulnerability Database (record CVE-2023-40000), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.