Server-Side Request Forgery in LiteSpeed Cache by LiteSpeed Technologies
CVE-2025-47437

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 September 2025

What is CVE-2025-47437?

A Server-Side Request Forgery (SSRF) vulnerability exists in LiteSpeed Cache, a product of LiteSpeed Technologies. This vulnerability could allow an attacker to manipulate requests sent from the server, potentially exposing sensitive data or enabling unauthorized actions. Versions n/a through 7.0.1 are affected, making it crucial for users to address this issue to protect their systems from exploitation.

Affected Version(s)

LiteSpeed Cache <= 7.0.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TaiYou (Patchstack Alliance)
.
CVE-2025-47437 : Server-Side Request Forgery in LiteSpeed Cache by LiteSpeed Technologies