Executive brief
LiteSpeed Cache is a popular WordPress plugin providing caching and performance optimization for websites. The plugin contains an unauthenticated server-side request forgery (SSRF) vulnerability that allows attackers to make the web server connect to internal systems, potentially exposing sensitive data behind firewalls and enabling lateral movement within corporate networks. No authentication is required to exploit this vulnerability, making it accessible to any attacker on the internet.
Technical details
The vulnerability is a server-side request forgery (SSRF) flaw in LiteSpeed Cache versions 7.9 and earlier that can be exploited without authentication. SSRF vulnerabilities allow attackers to induce the server to make HTTP requests to arbitrary destinations, including internal systems, cloud metadata endpoints, and other services. This can lead to information disclosure, internal service interaction, and potential elevation of privileges. The vulnerability is fixed in version 7.9.1 and later. The attack vector is network-based and requires no user interaction or privileges.
Affected products
- LiteSpeed Cache ≤7.9
Timeline
- 2026-09-03: disclosed
- 2026-09-02: patched: Version 7.9.1 released