Back to Security Advisories

LiteSpeed Cache for WordPress CVE-2026-84761: Server-Side Request Forgery (SSRF)

LiteSpeed Cache for WordPress is affected by CVE-2026-84761. Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache. Affected versions: all versions up to and including 7.9. CVSS base score: 7.2.

High 7.2 CVSS

Affected Versions

all versions up to and including 7.9

Default Update CMD

wp plugin update litespeed-cache

Fix Commands

All supported operating systems

wp plugin update litespeed-cache
# or: WordPress → Plugins → LiteSpeed Cache → Update Now
wp plugin get litespeed-cache --field=version

What this means under a SharedLicense license

Your SharedLicense license itself is not affected — this is a vulnerability in LiteSpeed Cache for WordPress (a free WordPress plugin), not in licensing. No license action is needed; update the plugin to protect the sites running on your servers.

Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-84761

Frequently Asked Questions

What is CVE-2026-84761?
Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache. Affected versions: all versions up to and including 7.9.
Is CVE-2026-84761 being exploited in the wild?
No confirmed public exploitation has been announced at the time of writing. With a CVSS base score of 7.2, apply the update on your next maintenance window and watch the vendor advisory for changes.
How do I fix CVE-2026-84761?
wp plugin update litespeed-cache. or: WordPress → Plugins → LiteSpeed Cache → Update Now. wp plugin get litespeed-cache --field=version.
Which versions are affected?
Affected: all versions up to and including 7.9. Update to the latest release.

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System