CVE-2025-47437: WordPress LiteSpeed Cache plugin <= 7.0.1 - Server Side Request Forgery (SSRF) vulnerability
Published Sep 9, 2025
·Updated
Server-Side Request Forgery (SSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 7.0.1.
Other sources
Server-Side Request Forgery (SSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache. This issue affects LiteSpeed Cache: from n/a through 7.0.1.
— NVD
Affected Software
1 affected component
Litespeed Technologies LiteSpeed Cache<=7.0.1
Remediation
Information
Update the WordPress LiteSpeed Cache plugin to the latest available version (at least 7.1).
Event History
Sep 9, 2025
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-47437?
CVE-2025-47437 is classified as a high-severity Server-Side Request Forgery (SSRF) vulnerability.
2
How do I fix CVE-2025-47437?
To mitigate CVE-2025-47437, update LiteSpeed Cache to version 7.0.2 or later.
3
What software is affected by CVE-2025-47437?
CVE-2025-47437 affects LiteSpeed Cache versions up to 7.0.1, including its WordPress plugin.
4
What are the potential impacts of CVE-2025-47437?
Exploitation of CVE-2025-47437 could allow attackers to make unauthorized network requests from the server.
5
When was CVE-2025-47437 disclosed?
CVE-2025-47437 was disclosed in December 2025.