CVE-2026-3375: LiteSpeed Cache <= 7.7 - Unauthenticated Stored Cross-Site Scripting via QUIC.cloud CCSS/UCSS REST API Endpoints

Published May 27, 2026
·
Updated

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/notifyccss and /wp-json/litespeed/v1/notifyucss REST API endpoints in all versions up to, and including, 7.7. These endpoints accept CSS content from QUIC.cloud callback notifications and store it to disk without sanitization. The stored content is later rendered inline frontend page loads without output escaping. The access control protecting these endpoints is IP-based validation that can potentially be bypassed when the WordPress site is deployed behind a reverse proxy, load balancer, or CDN with certain configurations. This makes it possible for unauthenticated attackers, under certain conditions, to inject arbitrary JavaScript into CCSS/UCSS content.

Affected Software

1 affected component
LiteSpeed LiteSpeed Cache for WordPress<=7.7

Event History

May 27, 2026
CVE Published
via MITRE·07:45 AM
Data Sourced
via MITRE·07:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-3375?

CVE-2026-3375 has a severity rating of high at 7.2.

2

What are the affected versions in CVE-2026-3375?

CVE-2026-3375 affects all versions of LiteSpeed Cache for WordPress up to and including 7.7.

3

How does CVE-2026-3375 exploit occur?

CVE-2026-3375 exploits occur through unauthenticated stored cross-site scripting via specific REST API endpoints.

4

How can I mitigate CVE-2026-3375?

To mitigate CVE-2026-3375, update the LiteSpeed Cache plugin to a version higher than 7.7.

5

What impacts does CVE-2026-3375 have?

CVE-2026-3375 can lead to potential data leaks and unauthorized access due to the cross-site scripting vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203