menu
techminis

A naukri.com initiative

google-web-stories
source image

Securityaffairs

1M

read

158

img
dot

Image Credit: Securityaffairs

WordPress LiteSpeed Cache plugin flaw could allow site takeover

  • A high-severity flaw in the WordPress LiteSpeed Cache plugin could allow attackers to execute arbitrary JavaScript code under certain conditions.
  • The vulnerability is a stored cross-site scripting (XSS) issue impacting versions up to 6.5.0.2.
  • The flaw arises from improper sanitization of the “X-LSCACHE-VARY-VALUE” HTTP header, allowing arbitrary script injection.
  • The vulnerability was addressed in version 6.5.1 on September 25, 2024.

Read Full Article

like

9 Likes

For uninterrupted reading, download the app