← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 19, 2026 · 09:16via CVEFeed

CVE-2026-76579 - LiteSpeed Cache = 7.9 - Reflected Cross-Site Scripting via ESI 'esi' Parameter

Brief

CVE ID : CVE-2026-76579

Published : Sept. 19, 2026, 9:16 a. m.

  • 11 hours, 40 minutes ago

Description : The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7. 9 due to insufficient input sanitization and output escaping.

This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Exploitation requires that the attacker supply a validly signed 'esi' value in the GET query string while submitting a separate attacker-controlled 'esi' payload as a POST body field, relying on PHP's default $_REQUEST merge order to have the POST value take precedence at the point of execution.

Severity: 4.7

  • MEDIUM
Read more on CVEFeed