Vulnerability Description
A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Litespeedtech | Litespeed Cache | < 3.6.1 |
Related Weaknesses (CWE)
References
- https://wordpress.org/plugins/litespeed-cache/#developersThird Party Advisory
- https://www.litespeedtech.com/products/cache-plugins/wordpress-accelerationProductVendor Advisory
- https://wordpress.org/plugins/litespeed-cache/#developersThird Party Advisory
- https://www.litespeedtech.com/products/cache-plugins/wordpress-accelerationProductVendor Advisory
FAQ
What is CVE-2020-29172?
CVE-2020-29172 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.
How severe is CVE-2020-29172?
CVE-2020-29172 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-29172?
Check the references section above for vendor advisories and patch information. Affected products include: Litespeedtech Litespeed Cache.