{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/litespeed-cache--7.8.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-18978"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LiteSpeed Cache (\u003c= 7.8.1)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress"],"_cs_type":"advisory","_cs_vendors":["LiteSpeed Technologies"],"content_html":"\u003cp\u003eLiteSpeed Cache for WordPress, in versions up to and including 7.8.1, contains a high-severity Stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-18978). The flaw resides in the plugin's insufficient sanitization and output escaping of user-supplied comment content. Specifically, attackers can bypass the WordPress \u003ccode\u003ewp_kses\u003c/code\u003e sanitization function by crafting payloads using decimal numeric character references (e.g., HTML entities for quotes, brackets) placed inside allowed HTML elements like \u003ccode\u003e\u0026lt;code\u0026gt;\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eBecause \u003ccode\u003ewp_kses\u003c/code\u003e fails to recognize certain patterns as dangerous HTML attributes when nested within allowed elements, malicious scripts can persist in the comment database. These scripts execute in the context of the browser for any user (including administrators) who visits the page containing the injected comment. Successful exploitation requires a specific configuration where the WordPress site allows comments from previously approved users and has the \u0026quot;require_name_email\u0026quot; setting disabled.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browsers of site visitors or administrators. This can lead to session hijacking, unauthorized actions performed on behalf of the victim (such as creating new administrative users or modifying site content), and credential theft. The impact is significant for high-traffic WordPress sites that allow user comments, particularly if site administrators frequently visit comment-heavy pages.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the LiteSpeed Cache plugin to the latest version immediately to remediate CVE-2026-18978.\u003c/li\u003e\n\u003cli\u003eAudit WordPress site settings to enable \u0026quot;require_name_email\u0026quot; for comments to increase the friction for unauthenticated attackers.\u003c/li\u003e\n\u003cli\u003eReview site comment moderation settings to ensure new comments from previously approved authors are held for review if the plugin update cannot be applied immediately.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious HTTP POST requests to the WordPress comment submission endpoint (\u003ccode\u003e/wp-comments-post.php\u003c/code\u003e) containing HTML numeric entities or script-like patterns.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T07:11:47Z","date_published":"2026-08-28T07:11:47Z","id":"https://feed.craftedsignal.io/briefs/2026-08-litespeed-xss/","summary":"An unauthenticated stored XSS vulnerability in LiteSpeed Cache versions 7.8.1 and below allows attackers to inject malicious scripts into WordPress comments by bypassing wp_kses input sanitization.","title":"Stored XSS in LiteSpeed Cache for WordPress via Comment Content","url":"https://feed.craftedsignal.io/briefs/2026-08-litespeed-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - LiteSpeed Cache (\u003c= 7.8.1)","version":"https://jsonfeed.org/version/1.1"}