CVE-2026-76579 - LiteSpeed Cache = 7.9 - Reflected Cross-Site Scripting via ESI 'esi' Parameter
Brief
CVE ID : CVE-2026-76579
Published : Sept. 19, 2026, 9:16 a. m.
- 11 hours, 40 minutes ago
Description : The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7. 9 due to insufficient input sanitization and output escaping.
This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Exploitation requires that the attacker supply a validly signed 'esi' value in the GET query string while submitting a separate attacker-controlled 'esi' payload as a POST body field, relying on PHP's default $_REQUEST merge order to have the POST value take precedence at the point of execution.
Severity: 4.7
- MEDIUM
