Security Update for LSCWP

We have a security update for LiteSpeed Cache for WordPress. Recently, we were made aware of a vulnerability in the LiteSpeed Cache for WordPress plugin. We patched it in v7.9.1.
To protect your WordPress sites, please update to the latest version of the LSCache plugin immediately.
This Server-Side Request Forgery vulnerability, reported by the Patchstack team, has been assigned CVE-2026-84761.
Impact
This vulnerability only affects sites where both of the following are true:
- The site is served through QUIC.cloud CDN
- The origin server does not restore the real visitor IP, so the QUIC.cloud proxy node’s address is what the site sees as
REMOTE_ADDR(in LiteSpeed Web Server, this means Use Client IP in Header is set toNo; other origin server types will configure this differently.)
With both in place, an unauthenticated attacker can cause the site to make server-side requests to internal or otherwise unreachable network locations, and then retrieve the full response, allowing sensitive internal resources to be exposed.
Because this requires the specific REMOTE_ADDR exposure described above, sites without that configuration are not affected.
Actions
We strongly recommend that every site upgrade to the plugin version 7.9.1 or higher to patch this vulnerability.
Timeline
- August 9, 2026: Patchstack alerted us to the issue.
- September 1, 2026: We patched the issue and released v7.9.1 to the WordPress repository
Conclusion
We thank Patchstack for bringing this issue to our attention. This vulnerability has been patched, so if you are keeping your LiteSpeed Cache plugin up-to-date, there is nothing you need to do. If you have not updated in a while, please do so today.
Comments