ZeroHour

CVE-2026-84761

mass

Unauthenticated SSRF in LiteSpeed Cache WordPress plugin (≤ 7.9)

CVSS 3.1
7.2 high
EPSS
<1%p5
Published
()
Modified
AI analysis

An unauthenticated Server Side Request Forgery (SSRF) flaw (CWE-918) exists in the LiteSpeed Cache plugin for WordPress in all versions up to and including 7.9. Because no authentication is required, any remote attacker can send a crafted request that makes the site's web server issue requests to attacker-controlled or internal-only URLs. Successful abuse can let an attacker probe the server's internal network, reach otherwise inaccessible services, and read or modify limited data, consistent with the changed-scope, high-severity (7.2) CVSS rating. Any WordPress site running LiteSpeed Cache 7.9 or older is affected, and the plugin's very large install base makes this a broadly deployed flaw. There is currently no public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days.

What to do: Update LiteSpeed Cache to a fixed version newer than 7.9 as soon as one is available (the data does not specify the patched release number). Until you can patch, restrict the web server's outbound network access (egress filtering) and/or apply WAF rules that block SSRF-style requests, and review server and application logs for unexpected outbound HTTP requests originating from the site.

Affected
LiteSpeed Technologies LiteSpeed Cache (WordPress plugin)<= 7.9
Estimated exposure
mass≈5,000,000+ WordPress sites (LiteSpeed Cache reports roughly 5M active installs on WordPress.org) — LiteSpeed Cache is one of the most-installed plugins on WordPress.org with on the order of 5 million active installs, so the exposed population is at least in the millions, though only installs running version 7.9 or older are vulnerable.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions.

Ecosystems
WordPress
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.