CVE-2024-47374
WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerability
Record summary
CVE-2024-47374 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template. VulnCheck reports CVE-2024-47374 use in known ransomware campaigns.
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through <= 6.5.0.2.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 19, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 7, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
LiteSpeed CacheBrowse LiteSpeed Technologies / LiteSpeed CacheDefault status: unaffected | CVE List | Through 6.5.0.2 | affected |
LiteSpeed CacheBrowse LiteSpeed Technologies / LiteSpeed Cache | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHLiteSpeed Cache <= 6.5.0.2 - Stored XSSCVSS 7.1
LiteSpeed Technologies LiteSpeed Cache versions up to 6.5.0.2 contain a stored cross-site scripting caused by improper input neutralization during web page generation, letting attackers execute malicious scripts in victim browsers, exploit requires storing malicious input.
Impact
Attackers can execute malicious scripts in victim browsers, leading to session hijacking, defacement, or redirection.
Remediation
Update to the latest version of LiteSpeed Cache.
Source: ProjectDiscovery