Unauthenticated Server Side Request Forgery in LiteSpeed Cache by LiteSpeed Technologies
CVE-2026-84761

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 September 2026

What is CVE-2026-84761?

LiteSpeed Cache versions up to 7.9 are vulnerable to an unauthenticated Server Side Request Forgery (SSRF). This vulnerability can allow attackers to send crafted requests to internal systems, potentially leading to unauthorized access and data exposure. It is crucial for users of LiteSpeed Cache to apply updates and security patches to mitigate risks associated with this type of attack.

Affected Version(s)

LiteSpeed Cache <= 7.9

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sicksec | Patchstack Bug Bounty Program
.