PT-2026-85102 · Litespeed Technologies · Litespeed Cache

CVE-2026-84761

·

Published

2026-09-03

·

Updated

2026-09-10

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
A critical security vulnerability was found in the LiteSpeed Cache plugin for WordPress, and you really need to patch it right now.
This flaw, tracked as CVE-2026-84761 with a high severity rating of 7.2, lets unauthenticated hackers pull off Server-Side Request Forgery attacks. Basically, anyone can trick your server into making bogus requests without even logging in. That means an attacker could snoop around your internal network, access hidden services, or steal sensitive data straight from your setup.
It affects every single installation running version 7.9 or older. Since over seven million sites rely on this plugin, hackers are definitely gonna exploit it big time.
To stay safe, log into your WordPress admin panel right away, go to your plugins section, and update LiteSpeed Cache to version 7.9.1 or higher immediately. Don't wait on this one.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84761

Affected Products

Litespeed Cache