Stored Cross-Site Scripting in LiteSpeed Cache Plugin for WordPress
CVE-2026-18978

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
28 August 2026

What is CVE-2026-18978?

The LiteSpeed Cache plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping techniques. This vulnerability allows unauthenticated attackers to inject arbitrary scripts through comment content. Specifically, attackers can exploit this weakness by utilizing decimal numeric character references within allowed HTML elements, bypassing WordPress's wp_kses sanitization mechanism. For successful exploitation, the site must permit users with previously approved comments to submit new ones, while also allowing the 'require_name_email' setting to be disabled, thus increasing the risk of malicious payload execution whenever a user accesses the compromised page.

Affected Version(s)

LiteSpeed Cache 0 <= 7.8.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jack Taylor
.