LiteSpeed Cache CVE-2023-4372: the 2023 stored-XSS fix

← All articles

LiteSpeed Cache CVE-2023-4372: the 2023 stored-XSS fix

Historical advisory: this article concerns a 2023 LiteSpeed Cache issue, not a newly discovered incident. The earlier title called it critical; Wordfence reported a CVSS score of 6.4, rated medium.

Affected versions and access

Wordfence identified stored cross-site scripting in LiteSpeed Cache versions through 5.6, involving the ESI shortcode. Insufficient input sanitization and output escaping could let authenticated users with contributor permissions or higher inject scripts. Do not describe this advisory as an unrestricted unauthenticated attack.

The historical fix

Version 5.7, released on 10 October 2023, addressed this issue. That is the historical fixed version, not a claim that 5.7 is the latest or appropriate version to install today. The advisory's installation count described potential exposure, not a confirmed number of compromised sites.

What site owners should do

Check the installed plugin and WordPress versions, apply currently supported updates from trusted sources, and review contributor accounts and unexpected content changes. Confirm who is responsible for updates and monitoring in your hosting agreement. A managed service does not guarantee that compromise is impossible, and an update does not reverse an existing intrusion.

Sources and further reading