Security Update for LSCWP
September 2nd, 2026

A server-side request forgery vulnerability reported by Patchstack has been announced. Please upgrade to v7.9.1 or later.

Security Update for LSCWP
August 27th, 2026

A cross-site scripting vulnerability reported by WordFence has been assigned CVE-2026-18978. Please upgrade to v7.9 or later.

Security Update for LSCWP
August 27th, 2026

A cross-site scripting vulnerability reported by WordFence has been assigned CVE-2026-3129. Please upgrade to v7.8 or later.

HTTP/2 Bomb Vulnerability
June 5th, 2026

LiteSpeed server products are effectively not vulnerable to HTTP/2 Bomb attacks. Learn why here.

Security Update for LSCWP
May 27th, 2026

We have a security update for LiteSpeed Cache for WordPress. A few months ago, we were made aware of a vulnerability in the LiteSpeed Cache for …

Security Update for LSCWP
October 29th, 2025

We have a security update for LiteSpeed Cache for WordPress. Recently we were made aware of a vulnerability in the LiteSpeed Cache for WordPress plugin. We …

LiteSpeed Security Update
August 18th, 2025

We have a security update for LiteSpeed’s QUIC and HTTP/3 Library (LSQUIC), and all three LiteSpeed server products. Recently we were made aware of a vulnerability …