
CVE-2024-51915 – LiteSpeed Cache <= 6.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2024-51915
20 Dec 2024 — The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-50550 – WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerability
https://notcve.org/view.php?id=CVE-2024-50550
29 Oct 2024 — Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a through 6.5.1. Vulnerabilidad de asignación incorrecta de privilegios en LiteSpeed Technologies LiteSpeed Cache permite la escalada de privilegios. Este problema afecta a LiteSpeed Cache: desde n/a hasta 6.5.1. The LiteSpeed Cache plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.1. This is due to th... • https://patchstack.com/database/vulnerability/litespeed-cache/wordpress-litespeed-cache-plugin-6-5-1-privilege-escalation-vulnerability?_s_id=cve • CWE-266: Incorrect Privilege Assignment •

CVE-2024-47637 – WordPress LiteSpeed Cache plugin <= 6.4.1 - Path Traversal vulnerability
https://notcve.org/view.php?id=CVE-2024-47637
30 Sep 2024 — : Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through 6.4.1. :Vulnerabilidad de Path Traversal relativo en LiteSpeed Technologies LiteSpeed Cache permite Path Traversal. Este problema afecta a LiteSpeed Cache: desde n/a hasta 6.4.1. The LiteSpeed Cache plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.4.1. This makes it possible for authenticated attackers, with a... • https://patchstack.com/database/vulnerability/litespeed-cache/wordpress-litespeed-cache-plugin-6-4-1-path-traversal-vulnerability?_s_id=cve • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-23: Relative Path Traversal •

CVE-2024-47373 – WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerability
https://notcve.org/view.php?id=CVE-2024-47373
30 Sep 2024 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 6.5.0.2. The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.5.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to ... • https://patchstack.com/database/vulnerability/litespeed-cache/wordpress-litespeed-cache-plugin-6-5-0-2-cross-site-scripting-xss-vulnerability-2?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-47374 – WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerability
https://notcve.org/view.php?id=CVE-2024-47374
30 Sep 2024 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 6.5.0.2. The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-LSCACHE-VARY-VALUE' header in all versions up to, and including, 6.5.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers t... • https://patchstack.com/database/vulnerability/litespeed-cache/wordpress-litespeed-cache-plugin-6-5-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-44000 – WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
https://notcve.org/view.php?id=CVE-2024-44000
05 Sep 2024 — Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a before 6.5.0.1. The LiteSpeed Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.4.1 through the debug.log file that is publicly exposed. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log file. The log file ... • https://packetstorm.news/files/id/181592 • CWE-522: Insufficiently Protected Credentials CWE-532: Insertion of Sensitive Information into Log File •

CVE-2023-40000 – WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability
https://notcve.org/view.php?id=CVE-2023-40000
27 Feb 2024 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7. Vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web ('cross-site Scripting') en LiteSpeed Technologies LiteSpeed Cache permite almacenar XSS. Este problema afecta a LiteSpeed Cache: desde n/a hasta 5.7. The LiteSpeed Cache plugin for WordPress is vulne... • https://github.com/rxerium/CVE-2023-40000 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-45000 – WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Broken Access Control on API vulnerability
https://notcve.org/view.php?id=CVE-2023-45000
27 Feb 2024 — Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cache: from n/a through 5.7. Vulnerabilidad de autorización faltante en LiteSpeed Technologies LiteSpeed Cache. Este problema afecta a LiteSpeed Cache: desde n/a hasta 5.7. The LiteSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the 'update_cdn_status' function in versions up to, and including, 5.7. This makes it possible for u... • https://patchstack.com/database/vulnerability/litespeed-cache/wordpress-litespeed-cache-plugin-5-7-unauthenticated-broken-access-control-on-api-vulnerability?_s_id=cve • CWE-862: Missing Authorization •