PT-2026-85102 · Litespeed Technologies · Litespeed Cache
CVE-2026-84761
·
Published
2026-09-03
·
Updated
2026-09-10
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
A critical security vulnerability was found in the LiteSpeed Cache plugin for WordPress, and you really need to patch it right now.
This flaw, tracked as CVE-2026-84761 with a high severity rating of 7.2, lets unauthenticated hackers pull off Server-Side Request Forgery attacks. Basically, anyone can trick your server into making bogus requests without even logging in. That means an attacker could snoop around your internal network, access hidden services, or steal sensitive data straight from your setup.
It affects every single installation running version 7.9 or older. Since over seven million sites rely on this plugin, hackers are definitely gonna exploit it big time.
To stay safe, log into your WordPress admin panel right away, go to your plugins section, and update LiteSpeed Cache to version 7.9.1 or higher immediately. Don't wait on this one.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Litespeed Cache