Stored Cross-Site Scripting Vulnerability in LiteSpeed Cache Plugin for WordPress
CVE-2024-9169
What is CVE-2024-9169?
The LiteSpeed Cache plugin for WordPress is prone to a Stored Cross-Site Scripting vulnerability stemming from inadequate input sanitization and output escaping mechanisms. This issue permits authenticated attackers with administrator-level permissions to inject arbitrary web scripts during the debug settings configuration. The injected scripts can execute whenever a user accesses a page containing the malicious payload. This vulnerability particularly impacts multi-site installations and systems where the 'unfiltered_html' capability has been disabled, making these environments especially susceptible to exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published