CVE · Medium

CVE-2021-24964 — LiteSpeed Cache [litespeed-cache] < 4.4.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24964 LiteSpeed Cache [litespeed-cache] < 4.4.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 4.4.4 4.4.4 2021-11-30

CVE-2021-24964

The LiteSpeed Cache plugin up to version 4.4.3 contains a flaw where it fails to adequately validate that incoming requests originate from QUIC.cloud servers, enabling attackers to craft requests to specific endpoints by spoofing an X-Forwarded-For header. One of these vulnerable endpoints permits CSS injection when a particular setting is active, and the injected code gets rendered on certain pages without proper sanitization or escaping. An unauthenticated attacker could exploit both weaknesses together to inject malicious JavaScript into pages that users visit.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.