CVE-2024-47373

WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through <= 6.5.0.2.


We have discovered 99,929 live websites that are affected by CVE-2024-47373.

Run a Free Instant Scan




Affected Software

Product  Litespeed Cache
Category Cache Tools
Vulnerable Domains99,929 live websites (10% of Litespeed Cache install base)
Vulnerable Versions
  • from 0 through 6.5.0.2
Vulnerable Versions Count125 versions ( 86% of all versions)



Details

  • Published - Oct 5, 2024
  • Updated - Apr 1, 2026

Credits

  • TaiYou | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2024-47373
United States26,085 websites



Poland6,428 websites
GB6,235 websites
Turkey6,169 websites
Canada5,019 websites
Spain4,306 websites
Romania3,687 websites
France3,604 websites
Germany3,603 websites
Vietnam2,916 websites

Website Distribution by TLD

Number of websites using CVE-2024-47373
.com44,932 websites
.pl4,770 websites
.org4,132 websites
.co.uk3,186 websites
.net2,802 websites
.com.br2,684 websites
.com.au1,784 websites
.ca1,682 websites
.es1,668 websites
.de1,105 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-47373

Top websites that are affected by CVE-2024-47373. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.fm United States*,***
***********.com Austria*,***
***********.net United States**,***
*******.com United States**,***
*********.com United States**,***
*********.com Germany**,***
******.com United States**,***
******.com Latvia**,***
*********.net United States**,***
****************.ai United States**,***
See full domain list

FAQ

A total of 99,929 websites have been identified as vulnerable to CVE-2024-47373, based on global website indexing conducted by WebTechSurvey.
The Litespeed Cache is affected by the CVE-2024-47373 vulnerability.
Litespeed Cache versions up to and including 6.5.0.2 are vulnerable to CVE-2024-47373.