A Cross-Site Scripting (XSS) vulnerability, officially designated as CVE-2023-40000, has been identified in the LiteSpeed Cache plugin. This flaw allows unauthorised individuals executing the script to gain complete control over your WordPress site.
The Technical Details
A vulnerability in the LiteSpeed Cache for WordPress (LSCWP) plugin, affecting versions 5.7.0.0 and earlier, potentially allows individuals without appropriate permissions to acquire admin privileges through the litespeed/v1/cdn_status endpoint.
Who’s Affected and What to Do
If you’re using a version of the LiteSpeed Cache plugin before 5.7.0.1, we strongly recommend that you upgrade to version 5.7.0.1 or newer to close this security loophole.
Upgrading Is Easy:
- Log in to your WordPress dashboard.
- Head over to the “Plugins” section.
- Check if Litespeed Cache is 5.7.0.1 or later. If not, click the “update now” button.