Impact
A server‑side request forgery vulnerability exists in LiteSpeed Cache plugin versions up to and including 7.0.1. The flaw allows an attacker to cause the WordPress server to fetch arbitrary resources, potentially exposing internal network endpoints or sensitive data. This issue is classified as CWE‑918.
Affected Systems
The affected product is LiteSpeed Technologies’ LiteSpeed Cache WordPress plugin. Any WordPress site running this plugin with a version 7.0.1 or older is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity, while the EPSS score of less than 1% implies a very low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves supplying a malicious URL or reference through the plugin’s request functionality, which is then used by the server to retrieve external resources.
OpenCVE Enrichment
EUVD