Security monitoring in Japan recorded a rise in exploitation attempts against CVE-2023-40000, an unauthenticated stored cross-site scripting flaw in the WordPress LiteSpeed Cache plugin. The vulnerability affects versions earlier than 5.7.0.1 and can be abused through the _msg parameter of the /wp-json/litespeed/v1/cdn_status endpoint, allowing attackers to inject malicious script content into WordPress files or databases.
Researchers said successful exploitation could also enable attackers to create administrator accounts, increasing the risk of full site compromise. Observed activity increased sharply from May 21, with many attack sources traced to the Netherlands and Switzerland, and defenders were urged to update LiteSpeed Cache to version 5.7.0.1 or later immediately.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
In its June 14, 2024 report covering May 2024, MBSD-SOC said attacks against CVE-2023-40000 had increased and that most observed attack sources were in the Netherlands and Switzerland. The report warned exploitation could embed unauthorized scripts in WordPress files or databases or enable creation of administrator users, and urged users to update promptly.
MBSD-SOC reported that detections of attacks targeting CVE-2023-40000 in the WordPress LiteSpeed Cache plugin increased starting on May 21, 2024. The observed exploit activity abused the vulnerable /wp-json/litespeed/v1/cdn_status endpoint and injected script content via the result[_msg] parameter.
WPScan described CVE-2023-40000 as an unauthenticated stored cross-site scripting vulnerability affecting LiteSpeed Cache versions earlier than 5.7.0.1.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.