{"id":13231,"date":"2026-05-27T10:42:21","date_gmt":"2026-05-27T14:42:21","guid":{"rendered":"https:\/\/blog.litespeedtech.com\/?p=13231"},"modified":"2026-05-27T10:42:21","modified_gmt":"2026-05-27T14:42:21","slug":"security-update-for-lscwp-cve-2026-3375","status":"publish","type":"post","link":"https:\/\/lswp.store\/index.php\/2026\/05\/27\/security-update-for-lscwp-cve-2026-3375\/","title":{"rendered":"Security Update for LSCWP"},"content":{"rendered":"<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter size-full wp-image-12875\" src=\"https:\/\/lswp.store\/wp-content\/uploads\/2024\/08\/lscwp-patches.png\" alt=\"Security patch for LiteSpeed Cache for WordPress\" width=\"1000\" height=\"500\" srcset=\"https:\/\/lswp.store\/wp-content\/uploads\/2024\/08\/lscwp-patches.png 1000w, https:\/\/lswp.store\/wp-content\/uploads\/2024\/08\/lscwp-patches-300x150.png 300w, https:\/\/lswp.store\/wp-content\/uploads\/2024\/08\/lscwp-patches-768x384.png 768w, https:\/\/lswp.store\/wp-content\/uploads\/2024\/08\/lscwp-patches-600x300.png 600w\" sizes=\"(max-width: 1000px) 100vw, 1000px\" \/><\/p>\n<p>We have a security update for LiteSpeed Cache for WordPress. A few months ago, we were made aware of a vulnerability in the LiteSpeed Cache for WordPress plugin. We patched it shortly thereafter, in v7.8.<\/p>\n<p>To protect your WordPress sites, please update to <a href=\"https:\/\/wordpress.org\/plugins\/litespeed-cache\/\">the latest version of the LSCache plugin<\/a> immediately.<\/p>\n<p>This cross-site scripting vulnerability, <a href=\"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/litespeed-cache\/litespeed-cache-77-unauthenticated-stored-cross-site-scripting-via-quiccloud-ccssucss-rest-api-endpoints\">reported by the WordFence team<\/a>, has been assigned <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-3375\">CVE-2026-3375<\/a>.<\/p>\n<h2>Impact<\/h2>\n<p>This vulnerability only affects those sites where one or both of the following settings are enabled in <strong>Page Optimization &gt; CCS Settings<\/strong>:<\/p>\n<ul>\n<li><strong>Generate UCSS<\/strong><\/li>\n<li><strong>Load CSS Asynchronously<\/strong><\/li>\n<\/ul>\n<p>Additionally, the site\u2019s server IP must be exposed, and there must be a QUIC.cloud- or Cloudflare-related misconfiguration in the site\u2019s WordPress code.<\/p>\n<p>With all of the above in place, the vulnerability may be exploited.<\/p>\n<p>Given that it requires a misconfiguration, we don\u2019t expect this vulnerability to be frequently exploited.<\/p>\n<h2>Actions<\/h2>\n<p>We recommend that every site upgrade to the plugin version 7.8 or higher to patch this vulnerability.<\/p>\n<h2>Timeline<\/h2>\n<ul>\n<li><strong>February 27, 2026<\/strong>: WordFence alerted us to the issue.<\/li>\n<li><strong>March 3, 2026<\/strong>: We patched the issue and released v7.8 to the WordPress repository<\/li>\n<li><strong>March 20, 2026<\/strong>: We added v7.8 to the list of stable releases in our control panel plugins<\/li>\n<\/ul>\n<h2>Conclusion<\/h2>\n<p>We thank WordFence for bringing this issue to our attention. This vulnerability has been patched, so if you are keeping your LiteSpeed Cache plugin up-to-date, there is nothing you need to do. If you have not updated in a while, please do so today.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We have a security update for LiteSpeed Cache for WordPress. A few months ago, we were made aware of a vulnerability in the LiteSpeed Cache for WordPress plugin. We patched it shortly thereafter, in v7.8. To protect your WordPress sites, please update to the latest version of the LSCache plugin immediately. This cross-site scripting vulnerability, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":12875,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[28,23],"tags":[316],"class_list":["post-13231","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cache","category-security","tag-wordpress"],"jetpack_featured_media_url":"https:\/\/lswp.store\/wp-content\/uploads\/2024\/08\/lscwp-patches.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/13231","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/comments?post=13231"}],"version-history":[{"count":0,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/13231\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media\/12875"}],"wp:attachment":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media?parent=13231"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/categories?post=13231"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/tags?post=13231"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}