CVE-2026-84761: WordPress LiteSpeed Cache plugin <= 7.9 - Server Side Request Forgery (SSRF) vulnerability
Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress LiteSpeed Cache pluginto a version that resolves this vulnerability.Fixed in 7.9.1
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation. It is remotely reachable according to the supplied vector.
Which installations are affected?
LiteSpeed Cache plugin versions 7.9 and earlier are identified as affected. The provided information does not state whether any particular plugin configuration is required.
What could an attacker do through this flaw?
This is an SSRF vulnerability, meaning an attacker may be able to cause the affected server to make requests. The supplied severity vector indicates low impacts to confidentiality and integrity, with no stated availability impact.