Impact
LiteSpeed Cache for WordPress has a reflected cross‑site scripting vulnerability in its ESI handling. Unauthenticated users can supply a signed 'esi' query parameter and an attacker‑controlled 'esi' POST body. Because PHP merges $_REQUEST with POST values taking precedence, the payload in the POST body is executed when the page renders, allowing arbitrary JavaScript injection. This enables cookie theft, session hijack, defacement, or malicious redirection.
Affected Systems
All installations of the LiteSpeed Cache plugin for WordPress with version 7.9 or earlier are affected, including the default 7.8.x series and the 7.9 release. The flaw originates in the esi.cls.php component shipped in these releases.
Risk and Exploitability
The CVSS base score of 4.7 reflects moderate severity, and the EPSS score of less than 1 % indicates a low exploitation probability in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to craft a URL containing a signed 'esi' GET parameter and to supply a malicious 'esi' value in a POST body, relying on PHP’s $_REQUEST merge order. Because the attack depends on a victim clicking a crafted link, the attack vector is indirect but can be effective against users who are not trained to recognize malicious URLs.
OpenCVE Enrichment