Description
The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the attacker supply a validly signed 'esi' value in the GET query string while submitting a separate attacker-controlled 'esi' payload as a POST body field, relying on PHP's default $_REQUEST merge order to have the POST value take precedence at the point of execution.
Published: 2026-09-19
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

LiteSpeed Cache for WordPress has a reflected cross‑site scripting vulnerability in its ESI handling. Unauthenticated users can supply a signed 'esi' query parameter and an attacker‑controlled 'esi' POST body. Because PHP merges $_REQUEST with POST values taking precedence, the payload in the POST body is executed when the page renders, allowing arbitrary JavaScript injection. This enables cookie theft, session hijack, defacement, or malicious redirection.

Affected Systems

All installations of the LiteSpeed Cache plugin for WordPress with version 7.9 or earlier are affected, including the default 7.8.x series and the 7.9 release. The flaw originates in the esi.cls.php component shipped in these releases.

Risk and Exploitability

The CVSS base score of 4.7 reflects moderate severity, and the EPSS score of less than 1 % indicates a low exploitation probability in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to craft a URL containing a signed 'esi' GET parameter and to supply a malicious 'esi' value in a POST body, relying on PHP’s $_REQUEST merge order. Because the attack depends on a victim clicking a crafted link, the attack vector is indirect but can be effective against users who are not trained to recognize malicious URLs.

Generated by OpenCVE AI on September 19, 2026 at 23:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade LiteSpeed Cache to version 7.9.1 or later, where the ESI handling issue has been fixed.
  • If an upgrade cannot be performed immediately, disable the ESI/Edge Side Includes feature in the plugin settings or remove the esi.cls.php file to prevent the vulnerable code from executing.
  • Deploy a web application firewall rule that blocks or sanitizes the 'esi' query parameter and rejects POST payloads containing malicious content, reducing the window of exposure.

Generated by OpenCVE AI on September 19, 2026 at 23:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Litespeedtech
Litespeedtech litespeed Cache
Wordpress
Wordpress wordpress
Vendors & Products Litespeedtech
Litespeedtech litespeed Cache
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the attacker supply a validly signed 'esi' value in the GET query string while submitting a separate attacker-controlled 'esi' payload as a POST body field, relying on PHP's default $_REQUEST merge order to have the POST value take precedence at the point of execution.
Title LiteSpeed Cache <= 7.9 - Reflected Cross-Site Scripting via ESI 'esi' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Litespeedtech Litespeed Cache
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T13:51:18.872Z

Reserved: 2026-08-19T14:03:14.526Z

Link: CVE-2026-76579

cve-icon Vulnrichment

Updated: 2026-09-19T13:48:34.342Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T09:16:34.443

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-76579

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:00:11Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')