Sale of a Vulnerability Bundle for the WordPress LiteSpeed Cache Plugin

Dark Web2026-08-31, 11:03
For informational purposes only.
Affected product: LiteSpeed Cache for WordPress 7.9 Vulnerability types: Information Disclosure / SSRF / Broken Access Control / Stored Content Injection / Cache Confusion
The seller claims to be offering multiple vulnerabilities affecting LiteSpeed Cache, one of the most widely used optimization and caching plugins for WordPress. At the time of the post, version 7.9, released on August 5, 2026, was the latest stable release. The official WordPress plugin directory lists more than 7 million active installations.
The first claimed issue is an unauthenticated disclosure of private site configuration data. According to the seller, under certain performance-related configurations, an attacker can obtain internal LiteSpeed Cache settings, including data associated with connected third-party services. The seller estimates that roughly 40% of installations could be affected.
The second vulnerability is described as an unauthenticated SSRF issue with full response read access and the ability to escalate into content modification. The seller claims that the issue appears under certain CDN trust configurations and may affect around 2–5% of installations. Potential impact is said to include access to internal services and cloud infrastructure.
The third issue involves exposure of LiteSpeed Cache service and backup files on nginx-fronted configurations. According to the seller, these files may contain private site settings and credentials or configuration data related to third-party integrations.
The fourth vulnerability is described as broken access control affecting cache-management operations. Under certain conditions, a low-privileged authenticated user, or a CSRF attack targeting such a user, could allegedly trigger arbitrary cache purges. The seller states that the impact is limited to availability and forced content regeneration.
The fifth issue is a stored content injection vulnerability affecting live pages. According to the seller, it has already been fixed in version 7.9 and is therefore an N-day issue for installations running version 7.8.1 or earlier. The claimed impact includes persistent page modification and the ability to display phishing-style overlays.
The sixth claimed vulnerability involves visitor identity confusion at the cache layer. According to the seller, it does not provide direct access to another user’s account, but can be chained with the first issue. The seller deliberately withholds the exact exploitation requirements.
LiteSpeed Cache 7.9 was released on August 5, 2026. LiteSpeed Cache has a very large global footprint. In addition to the more than 7 million active installations listed by WordPress.org, BuiltWith detects LiteSpeed Cache on approximately 17.6 million websites worldwide and ranks it among the most widely deployed caching technologies.
Vendors
Litespeed Technologies
Products
Builtwith
Litespeed Cache
Litespeed Cache 7.9
Litespeed Cache For Wordpress
Litespeed Cache For Wordpress 7.9
Nginx
More