{"id":13079,"date":"2025-05-07T14:52:57","date_gmt":"2025-05-07T18:52:57","guid":{"rendered":"https:\/\/blog.litespeedtech.com\/?p=13079"},"modified":"2025-05-07T14:52:57","modified_gmt":"2025-05-07T18:52:57","slug":"litespeed-cache-v71-patch","status":"publish","type":"post","link":"https:\/\/lswp.store\/index.php\/2025\/05\/07\/litespeed-cache-v71-patch\/","title":{"rendered":"LSCWP Responsive Placeholders Patch"},"content":{"rendered":"<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter size-full wp-image-13081\" src=\"https:\/\/lswp.store\/wp-content\/uploads\/2025\/04\/lscwp-71-patch.png\" alt=\"LiteSpeed Cache v7.1 Patch\" width=\"1000\" height=\"500\" srcset=\"https:\/\/lswp.store\/wp-content\/uploads\/2025\/04\/lscwp-71-patch.png 1000w, https:\/\/lswp.store\/wp-content\/uploads\/2025\/04\/lscwp-71-patch-300x150.png 300w, https:\/\/lswp.store\/wp-content\/uploads\/2025\/04\/lscwp-71-patch-768x384.png 768w, https:\/\/lswp.store\/wp-content\/uploads\/2025\/04\/lscwp-71-patch-600x300.png 600w\" sizes=\"(max-width: 1000px) 100vw, 1000px\" \/><\/p>\n<p>We have a security update for LiteSpeed Cache for WordPress. Recently we were made aware of a vulnerability in the LiteSpeed Cache for WordPress plugin. We patched this vulnerability in v7.1.<\/p>\n<p>To protect your WordPress sites, please update to the latest version of the LSCache plugin immediately.<\/p>\n<p>This Server Side Request Forgery vulnerability, <a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/litespeed-cache\/vulnerability\/wordpress-litespeed-cache-plugin-7-0-1-server-side-request-forgery-ssrf-vulnerability\">reported by the Patchstack team<\/a>, has been assigned <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-47437\">CVE-2025-47437<\/a>.<\/p>\n<h2>Impact<\/h2>\n<p>This vulnerability affects those using <strong>Responsive Placeholders<\/strong>, and having the following configuration:<\/p>\n<ul>\n<li><strong>Media Settings &gt; Lazy Load Images<\/strong> must be <code>ON<\/code><\/li>\n<li><strong>Media Settings &gt; Responsive Placeholders<\/strong> must be <code>ON<\/code><\/li>\n<\/ul>\n<p>With both of these settings in place, the vulnerability may be exploited by a user with <code>unfiltered_html<\/code> capability and the ability to create a new post with a Custom HTML block.<\/p>\n<p>NOTE: by default, only <code>Editor<\/code>, <code>Admin<\/code>, and <code>Super Admin<\/code> roles have the <code>unfiltered_html<\/code> capability, but admins may assign it to other roles on a case-by-case basis via a plugin or custom code.<\/p>\n<h2>Actions<\/h2>\n<p>We suggest that every site upgrade to the plugin version 7.1 or higher to patch this low-severity vulnerability.<\/p>\n<h2>Timeline<\/h2>\n<ul>\n<li>April 10, 2025: Patchstack alerted us to the issue.<\/li>\n<li>April 24, 2025: We patched the issue and released v7.1 to the WordPress repository.<\/li>\n<li>April 30, 2025: We added v7.1 to the list of stable releases in our control panel plugins.<\/li>\n<\/ul>\n<h2>Conclusion<\/h2>\n<p>We thank Patchstack for bringing this issue to our attention. This vulnerability has been patched, so if you are keeping your LiteSpeed Cache plugin up-to-date, there is nothing you need to do. If you have not updated in a while, please do so today.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Details about the recent LiteSpeed Cache v7.1 patch, which fixes CVE-2025-47437, a potential Server Side Request Forgery vulnerability.<\/p>\n","protected":false},"author":1,"featured_media":13081,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[28,23],"tags":[316],"class_list":["post-13079","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cache","category-security","tag-wordpress"],"jetpack_featured_media_url":"https:\/\/lswp.store\/wp-content\/uploads\/2025\/04\/lscwp-71-patch.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/13079","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/comments?post=13079"}],"version-history":[{"count":0,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/13079\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media\/13081"}],"wp:attachment":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media?parent=13079"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/categories?post=13079"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/tags?post=13079"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}