Security Update for LSCWP

September 18th, 2026 by LSCache , Security 0 Comments

Security patch for LiteSpeed Cache for WordPress

We have a security update for LiteSpeed Cache for WordPress. Recently, we were made aware of a vulnerability in the LiteSpeed Cache for WordPress plugin. We patched it, in v7.9.1.

To protect your WordPress sites, please update to the latest version of the LSCache plugin immediately.

This Cross-Site Scripting vulnerability, reported by the WordFence team, has been assigned CVE-2026-76579.

Impact

This vulnerability only affects sites where all of the following are true:

  • Cache > Cache > Enable Cache is set to ON
  • Cache > ESI > Enable ESI is set to ON
  • The site has at least one public post with comments enabled

With these settings in place, an unauthenticated attacker may be able to entice a visitor to open a malicious page. Doing so can cause attacker-controlled JavaScript to run, acting with that visitor’s permissions (including potentially admin permissions) if the visitor is logged in.

The attacker does not need to have an account, and exploitation requires the victim to visit the attacker’s page.

Actions

We recommend that every site upgrade to the plugin version 7.9.1 or higher to patch this vulnerability.

Timeline

  • August 19, 2026: WordFence alerted us to the issue.
  • September 1, 2026: We patched the issue and released v7.9.1 to the WordPress repository
  • September 4, 2026: We added v7.9.1 to the list of stable releases in our control panel plugins

Conclusion

We thank WordFence for bringing this issue to our attention. This vulnerability has been patched, so if you are keeping your LiteSpeed Cache plugin up-to-date, there is nothing you need to do. If you have not updated in a while, please do so today.


Tags:
Categories:LSCache , Security

Related Posts


Comments