PT-2026-85102 · Litespeed Technologies · Litespeed Cache

CVE-2026-84761

·

Publicado

2026-09-03

·

Atualizado

2026-09-10

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
A critical security vulnerability was found in the LiteSpeed Cache plugin for WordPress, and you really need to patch it right now.
This flaw, tracked as CVE-2026-84761 with a high severity rating of 7.2, lets unauthenticated hackers pull off Server-Side Request Forgery attacks. Basically, anyone can trick your server into making bogus requests without even logging in. That means an attacker could snoop around your internal network, access hidden services, or steal sensitive data straight from your setup.
It affects every single installation running version 7.9 or older. Since over seven million sites rely on this plugin, hackers are definitely gonna exploit it big time.
To stay safe, log into your WordPress admin panel right away, go to your plugins section, and update LiteSpeed Cache to version 7.9.1 or higher immediately. Don't wait on this one.

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-84761

Produtos afetados

Litespeed Cache