Security Update for LSCWP

August 27th, 2026 by LSCache , Security 0 Comments

Security patch for LiteSpeed Cache for WordPress

We have a security update for LiteSpeed Cache for WordPress. Several months ago, we were made aware of a vulnerability in the LiteSpeed Cache for WordPress plugin. We patched it shortly thereafter, in v7.8.

To protect your WordPress sites, please update to the latest version of the LSCache plugin immediately.

This cross-site scripting vulnerability, reported by the WordFence team, has been assigned CVE-2026-3129.

Impact

This vulnerability only affects those sites where the following settings are enabled in Page Optimization > Media:

  • Lazy Load Images
  • Add Missing Sizes

With both of these settings in place, the vulnerability may be exploited when a bad actor with Author role or higher creates a post with the payload code inserted. The post must then be viewed by a non-logged-in user.

We don’t expect this vulnerability to be frequently exploited.

Actions

As this issue was resolved in v7.8 some time ago and we have already released v7.9 since then, we imagine most of you have already upgraded. If you have not, we recommend that you get caught up to the most recent version, as soon as possible.

Timeline

  • February 24, 2026: WordFence alerted us to the issue.
  • March 3, 2026: We patched the issue and released v7.8 to the WordPress repository
  • March 20, 2026: We added v7.8 to the list of stable releases in our control panel plugins

Conclusion

We thank WordFence for bringing this issue to our attention. This vulnerability has been patched, so if you are keeping your LiteSpeed Cache plugin up-to-date, there is nothing you need to do. If you have not updated in a while, please do so today.


Tags:
Categories:LSCache , Security

Related Posts


Comments