CVE-2021-24964 - CVE House
Back to Database
Status published Unknown CVE-2021-24964

LiteSpeed Cache < 4.4.4 - IP Check Bypass to Unauthenticated Stored XSS

Vulnerability Description

The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud servers, allowing attackers to make requests to certain endpoints by using a specific X-Forwarded-For header value. In addition, one of the endpoint could be used to set CSS code if a setting is enabled, which will then be output in some pages without being sanitised and escaped. Combining those two issues, an unauthenticated attacker could put Cross-Site Scripting payloads in pages visited by users.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-24964

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Emil Kylander

Affected Vendor

Affected Software

LiteSpeed Cache
Vulnerable Versions:
4.4.4

Timeline

Official Publish: January 3rd, 2022
Last Modified: May 22nd, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)