CVE-2026-84761
massUnauthenticated SSRF in LiteSpeed Cache WordPress plugin (≤ 7.9)
An unauthenticated Server Side Request Forgery (SSRF) flaw (CWE-918) exists in the LiteSpeed Cache plugin for WordPress in all versions up to and including 7.9. Because no authentication is required, any remote attacker can send a crafted request that makes the site's web server issue requests to attacker-controlled or internal-only URLs. Successful abuse can let an attacker probe the server's internal network, reach otherwise inaccessible services, and read or modify limited data, consistent with the changed-scope, high-severity (7.2) CVSS rating. Any WordPress site running LiteSpeed Cache 7.9 or older is affected, and the plugin's very large install base makes this a broadly deployed flaw. There is currently no public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days.
What to do: Update LiteSpeed Cache to a fixed version newer than 7.9 as soon as one is available (the data does not specify the patched release number). Until you can patch, restrict the web server's outbound network access (egress filtering) and/or apply WAF rules that block SSRF-style requests, and review server and application logs for unexpected outbound HTTP requests originating from the site.
| LiteSpeed Technologies LiteSpeed Cache (WordPress plugin) | <= 7.9 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.