CVE-2023-40000

✓ Confirmed 0-Day
Triaged: March 20, 2026 3 articles

EPSS Score

Source: FIRST.org · 2026-05-24
80.69%
probability
This CVE has a 80.69% probability of being exploited in the next 30 days.
0% Top 99.2th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Exploits & PoC

quantiom/litespeed-cache-xss-poc

PoC for XSS vulnerability in the LiteSpeed Cache WordPress plugin (CVE-2023-40000) allowing elevated privileges. Includes code, explanations, and miti

5
iveresk/cve-2023-40000

That's a PoC of cve-2023-40000. Wordpress LiteSpeed Cache exploit.

1
2 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
78%
EPSS 80.69%
Mentions 3

CNA Information

Analyst Note

CVE-2023-40000 in LiteSpeed Cache is explicitly documented as actively exploited in the wild (rogue admin account creation by threat actors per WPScan/TheHackerNews). The vulnerability was patched in October 2023 (version 5.7.0.1), and exploitation reports appear contemporaneous with or immediately following patch availability, meeting zero-day exploitation criteria.

Threat Actors 3

TA577
apt_group 🇷🇺 RU
NARWHAL SPIDER
apt_group 🇷🇺 RU
Moskalvzapoe
apt_group 🇷🇺 RU

Triage Info

Decided atMar 20, 2026