The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up to, and including, 6.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
We have discovered 216,116 live websites that are affected by CVE-2024-9169.
Product | ![]() |
Category | Cache Tools |
Vulnerable Domains | 216,116 live websites (23.55% of Litespeed Cache install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 148 versions ( 94.87% of all versions) |
![]() | 72,316 websites |
![]() | 14,433 websites |
![]() | 13,268 websites |
![]() | 11,194 websites |
![]() | 10,616 websites |
![]() | 9,360 websites |
![]() | 8,814 websites |
![]() | 7,075 websites |
![]() | 6,002 websites |
![]() | 5,530 websites |
.com | 97,873 websites |
.pl | 11,292 websites |
.org | 9,033 websites |
.net | 6,500 websites |
.co.uk | 6,366 websites |
.com.br | 6,242 websites |
.com.au | 4,160 websites |
.es | 3,299 websites |
.ca | 3,219 websites |
.nl | 2,851 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*******.fm | ![]() | *,*** | |
***********.com | ![]() | *,*** | |
***************************.***.mx | ![]() | *,*** | |
*********.com | ![]() | *,*** | |
*********.***********.eu | ![]() | **,*** | |
***********.net | ![]() | **,*** | |
*******.net | ![]() | **,*** | |
*******.net | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
*****.co | ![]() | **,*** |
FAQ