CVE-2021-24964
The LiteSpeed Cache plugin up to version 4.4.3 contains a flaw where it fails to adequately validate that incoming requests originate from QUIC.cloud servers, enabling attackers to craft requests to specific endpoints by spoofing an X-Forwarded-For header. One of these vulnerable endpoints permits CSS injection when a particular setting is active, and the injected code gets rendered on certain pages without proper sanitization or escaping. An unauthenticated attacker could exploit both weaknesses together to inject malicious JavaScript into pages that users visit.
Based on public CVE data (MITRE/NVD).