A vulnerability in the WordPress plugin LiteSpeed Cache could allow unauthorized users to gain privileges on vulnerable sites.

The vulnerability is tracked as CVE-2023-40000 and was addressed in October 2023 with version 5.7.0.1.
According to Patchstack Rafie Muhammad, this is a cross-site scripting vulnerability that could allow any unauthenticated user to steal sensitive information and gain more privileges on vulnerable WordPress sites by executing a single HTTP request.
See also: Ultimate Member: Critical vulnerability in WordPress plugin
LiteSpeed Cache is a plugin used to improve website and has over five million installations. The latest version of the plugin is version 6.1, which was released on February 5, 2024.
The vulnerability results from user input sanitization and escaping output. The vulnerability is located in a function named update_cdn_status() and can be reproduced in a default installation.
"Since the XSS payload appears as an admin notice and the admin notice could appear on any wp-admin endpoint, this vulnerability could also be easily triggered by any user with access to the wp-admin area," the researcher said.
See also: Hackers exploit vulnerability in Bricks Builder WordPress Theme
A few months ago, another vulnerability was discovered in the WordPress plugin LiteSpeed Cache, which was similar to the new bug. It was addressed in version 5.7.
Importance of WordPress protection
Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.

Additionally, an unsecured WordPress site can undermine the trust and credibility you have built with customers . If their data is compromised, they are likely to take legal action against you and switch to other companies.
See also: Balada Injector Malware has infected 6,700 WordPress sites
Securing your website is also important for maintaining the consistency and credibility of your content. If a hacker breaks into your website and corrupts the content, it can give the impression that you are not doing enough with your website.
In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining your customers’ trust, preserving your company’s reputation, and staying on top of the competition.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews.com
