CVE-2024-9169
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Sep 25, 2024
Updated: Mar 7, 2025
CWE ID 79
Summary
CVE-2024-9169 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the LiteSpeed Cache plugin for WordPress. The issue lies in the plugin's debug settings, which lack proper input sanitization and output escaping, allowing authenticated attackers with administrator-level permissions to inject malicious web scripts. These scripts will execute whenever an user accesses an injected page. This vulnerability only poses a threat to multi-site installations and installations where unfiltered_html has been disabled.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- LiteSpeed Cache plugin
Affected Vendors
- LiteSpeed Technologies Inc