Security Update for LSCWP

August 27th, 2026 by LSCache , Security 0 Comments

Security patch for LiteSpeed Cache for WordPress

We have a security update for LiteSpeed Cache for WordPress. Recently, we were made aware of a vulnerability in the LiteSpeed Cache for WordPress plugin. We patched it right away, in v7.9.

To protect your WordPress sites, please update to the latest version of the LSCache plugin immediately.

This Cross-Site Scripting vulnerability, reported by the WordFence team, has been assigned CVE-2026-18978.

Impact

The vulnerability only affects sites with the following plugin setting:

  • LiteSpeed Cache > Image Optimization > Image Optimization Settings > Next-Gen Image Format: set to WebP or AVIF

Additionally, the attacker must have the ability to publish a comment without moderation. This happens under either of these conditions in Settings > Discussion:

  • Comment author must have a previously approved comment is unchecked — so comments are auto-approved, or
  • Comment author must have a previously approved comment is checked and Comment author must fill out name and email is checked — allowing an attacker to reuse the name and email of a previously approved commenter to get auto-approved.

With these settings in place, unauthenticated attackers can inject arbitrary web scripts via comments that will execute whenever a user accesses an injected page.

Actions

We recommend that every site upgrade to the plugin version 7.9 or higher to patch this vulnerability.

Timeline

  • August 5, 2026: WordFence alerted us to the issue.
  • August 5, 2026: We patched the issue and released v7.9 to the WordPress repository

Conclusion

We thank WordFence for bringing this issue to our attention. This vulnerability has been patched, so if you are keeping your LiteSpeed Cache plugin up-to-date, there is nothing you need to do. If you have not updated in a while, please do so today.


Tags:
Categories:LSCache , Security

Related Posts


Comments