Impact
This vulnerability in the LiteSpeed Cache WordPress plugin arises from a flawed regular expression that attempts to strip the width and height attributes from images when the Lazy Load Images or Add Missing Sizes features are turned on. The defect permits an authenticated attacker with Author or higher permissions to place a malicious <img> tag with crafted attribute values into the media library or other content areas. When a page containing that image is viewed, the embedded JavaScript runs in the visitor’s browser, allowing the attacker to affect the display or behaviour of the page.
Affected Systems
All installations of the LiteSpeed Cache plugin for WordPress up to and including version 7.7 are vulnerable when the Lazy Load Images or Add Missing Sizes options are enabled. The affected product is listed as litespeedtech:LiteSpeed Cache by the CNA.
Risk and Exploitability
The CVSS score of 6.4 places the issue in the medium‑severity range. The EPSS score is reported as < 1 %, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker only requires author‑level access, which is commonly granted, and must use the image handling features of the plugin to inject the payload; the impact is confined to browsers that view the affected page.
OpenCVE Enrichment