Stored Cross-Site Scripting in LiteSpeed Cache Plugin for WordPress
CVE-2026-18978
What is CVE-2026-18978?
The LiteSpeed Cache plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping techniques. This vulnerability allows unauthenticated attackers to inject arbitrary scripts through comment content. Specifically, attackers can exploit this weakness by utilizing decimal numeric character references within allowed HTML elements, bypassing WordPress's wp_kses sanitization mechanism. For successful exploitation, the site must permit users with previously approved comments to submit new ones, while also allowing the 'require_name_email' setting to be disabled, thus increasing the risk of malicious payload execution whenever a user accesses the compromised page.
Affected Version(s)
LiteSpeed Cache 0 <= 7.8.1