CVE-2023-4372




The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in versions up to, and including, 5.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.



We have discovered 257,480 live websites that are affected by CVE-2023-4372.

Contact us to get more info




Affected Software

Product  Litespeed Cache
Category Cache Tools
Vulnerable Versions
  • from 0 through 5.6
Total Vulnerable Versions113
Vulnerable Domains257,480 live websites (29.83% of Litespeed Cache install base)



Details

  • Published - Jan 11, 2024
  • Updated - Jan 11, 2024

Credits

  • István Márton (finder)




Countries

United States63,320 websites



GB17,034 websites
Poland14,627 websites
Turkey14,067 websites
Canada11,726 websites
Spain10,486 websites
Cyprus9,872 websites
Brazil9,299 websites
India8,603 websites
France8,236 websites

TLDs

.com121,731 websites
.org11,298 websites
.pl11,222 websites
.co.uk9,388 websites
.com.br8,062 websites
.net7,892 websites
.com.au4,896 websites
.es3,778 websites
.ca3,587 websites
.nl3,286 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2023-4372

Top websites that are affected by CVE-2023-4372. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***.tw Taiwan*,***
***.*****.***.tw Taiwan*,***
*******.fm United States*,***
**********.ro Romania**,***
***.***********.***.br Brazil**,***
***************.com Australia**,***
***.*****************.net United States**,***
***.****.de Germany**,***
*********.com Germany**,***
******.com United States**,***
See full domain list