CVE-2026-3375: LiteSpeed Cache <= 7.7 - Unauthenticated Stored Cross-Site Scripting via QUIC.cloud CCSS/UCSS REST API Endpoints
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/notifyccss and /wp-json/litespeed/v1/notifyucss REST API endpoints in all versions up to, and including, 7.7. These endpoints accept CSS content from QUIC.cloud callback notifications and store it to disk without sanitization. The stored content is later rendered inline frontend page loads without output escaping. The access control protecting these endpoints is IP-based validation that can potentially be bypassed when the WordPress site is deployed behind a reverse proxy, load balancer, or CDN with certain configurations. This makes it possible for unauthenticated attackers, under certain conditions, to inject arbitrary JavaScript into CCSS/UCSS content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3375?
CVE-2026-3375 has a severity rating of high at 7.2.
What are the affected versions in CVE-2026-3375?
CVE-2026-3375 affects all versions of LiteSpeed Cache for WordPress up to and including 7.7.
How does CVE-2026-3375 exploit occur?
CVE-2026-3375 exploits occur through unauthenticated stored cross-site scripting via specific REST API endpoints.
How can I mitigate CVE-2026-3375?
To mitigate CVE-2026-3375, update the LiteSpeed Cache plugin to a version higher than 7.7.
What impacts does CVE-2026-3375 have?
CVE-2026-3375 can lead to potential data leaks and unauthorized access due to the cross-site scripting vulnerability.