{"id":13187,"date":"2025-10-29T17:34:56","date_gmt":"2025-10-29T21:34:56","guid":{"rendered":"https:\/\/blog.litespeedtech.com\/?p=13187"},"modified":"2025-10-29T17:34:56","modified_gmt":"2025-10-29T21:34:56","slug":"security-update-for-lscwp","status":"publish","type":"post","link":"https:\/\/lswp.store\/index.php\/2025\/10\/29\/security-update-for-lscwp\/","title":{"rendered":"Security Update for LSCWP"},"content":{"rendered":"<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter size-full wp-image-12875\" src=\"https:\/\/lswp.store\/wp-content\/uploads\/2024\/08\/lscwp-patches.png\" alt=\"Security patch for LiteSpeed Cache for WordPress\" width=\"1000\" height=\"500\" srcset=\"https:\/\/lswp.store\/wp-content\/uploads\/2024\/08\/lscwp-patches.png 1000w, https:\/\/lswp.store\/wp-content\/uploads\/2024\/08\/lscwp-patches-300x150.png 300w, https:\/\/lswp.store\/wp-content\/uploads\/2024\/08\/lscwp-patches-768x384.png 768w, https:\/\/lswp.store\/wp-content\/uploads\/2024\/08\/lscwp-patches-600x300.png 600w\" sizes=\"(max-width: 1000px) 100vw, 1000px\" \/><\/p>\n<p>We have a security update for LiteSpeed Cache for WordPress. Recently we were made aware of a vulnerability in the LiteSpeed Cache for WordPress plugin. We patched this vulnerability earlier this month, in v7.6.<\/p>\n<p>To protect your WordPress sites, please update to <a href=\"https:\/\/wordpress.org\/plugins\/litespeed-cache\/\">the latest version of the LSCache plugin<\/a> immediately.<\/p>\n<p>This cross-site scripting vulnerability, reported by the Trustwave team, has been assigned <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-12450\">CVE-2025-12450<\/a>.<\/p>\n<h2>Impact<\/h2>\n<p>This vulnerability only affects those who have debug enabled:<\/p>\n<ul>\n<li><strong>Debug Log <\/strong>must be <code>ON<\/code> or <code>Admin IP Only<\/code><\/li>\n<li><strong>Enable Cache<\/strong> must be <code>ON<\/code><\/li>\n<\/ul>\n<p>With both of these settings in place, the vulnerability may be exploited when a visitor accesses a link with a particular malicious string appended to the URL.<\/p>\n<p>Since it\u2019s not common to turn on debug mode and keep it on, we don\u2019t expect this vulnerability to be frequently exploited.<\/p>\n<h2>Actions<\/h2>\n<p>We recommend that every site upgrade to the plugin version 7.6 or higher to patch this vulnerability.<\/p>\n<h2>Timeline<\/h2>\n<ul>\n<li><strong>October 14, 2025<\/strong>: Trustwave alerted us to the issue.<\/li>\n<li><strong>October 15, 2025<\/strong>: We patched the issue and released v7.6 to the WordPress repository<\/li>\n<li><strong>October 21, 2025<\/strong>: We added v7.6 to the list of stable releases in our control panel plugins<\/li>\n<\/ul>\n<h2>Conclusion<\/h2>\n<p>We thank Trustwave for bringing this issue to our attention. This vulnerability has been patched, so if you are keeping your LiteSpeed Cache plugin up-to-date, there is nothing you need to do. If you have not updated in a while, please do so today.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We have a security update for LiteSpeed Cache for WordPress. Recently we were made aware of a vulnerability in the LiteSpeed Cache for WordPress plugin. We patched this vulnerability earlier this month, in v7.6. To protect your WordPress sites, please update to the latest version of the LSCache plugin immediately. This cross-site scripting vulnerability, reported [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":12875,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[19,28,23],"tags":[316],"class_list":["post-13187","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-slider","category-cache","category-security","tag-wordpress"],"jetpack_featured_media_url":"https:\/\/lswp.store\/wp-content\/uploads\/2024\/08\/lscwp-patches.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/13187","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/comments?post=13187"}],"version-history":[{"count":0,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/13187\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media\/12875"}],"wp:attachment":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media?parent=13187"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/categories?post=13187"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/tags?post=13187"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}