DIRAS TAKE
Treat this as urgent: there is no vendor patch available and the flaw enables stored XSS that executes in site visitors' browsers, increasing the risk to users and site sessions.
What is CVE-2026-18978?
An attacker can inject persistent JavaScript into pages served by the LiteSpeed Cache WordPress plugin, allowing scripts to run in visitors' browsers (CVE-2026-18978). Versions 7.8.1 and earlier in the 7.x branch are affected. Exploitation requires the site to permit users with previously approved comments to post new comments and have the require_name_email setting disabled, which lets a specially crafted comment bypass sanitization and reach the vulnerable output path. The weakness is classified as CWE-79 (Cross-site Scripting).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Which versions of litespeedtech LiteSpeed Cache are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | 7.8.1 and earlier |
Is CVE-2026-18978 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-18978
- Disable or restrict the comment feature until a vendor fix is released.
- Enable require_name_email and tighten comment moderation to prevent new unvetted posts.
- Apply strict input sanitization or remove allowed elements that permit numeric character references in comments.
- Monitor web logs and page content for unexpected script injections and follow vendor guidance when published.
Frequently asked questions
Is CVE-2026-18978 being actively exploited?
There are no public reports of active exploitation of CVE-2026-18978 as of 2026-09-29.
Which LiteSpeed Cache versions are affected by CVE-2026-18978?
LiteSpeed Cache versions 7.8.1 and earlier in the 7.x branch are listed as affected.
Is there a patch for CVE-2026-18978?
No patch is available according to the known facts; vendors have not listed fixed versions.
Does CVE-2026-18978 require authentication?
Exploitation depends on site comment settings: it requires that users with previously approved comments can post new comments and that require_name_email is disabled, rather than a standard authenticated account.
References
- nvd.nist.gov/vuln/detail/CVE-2026-18978
- cve.org/CVERecord?id=CVE-2026-18978
- wordfence.com/threat-intel/vulnerabilities/id/0b045f3d-8412-4e35-b369-2b485639274d?source=cve
- plugins.trac.wordpress.org/browser/litespeed-cache/trunk/src/media.cls.php#L1405
- plugins.trac.wordpress.org/browser/litespeed-cache/trunk/src/media.cls.php#L1358
- plugins.trac.wordpress.org/browser/litespeed-cache/trunk/src/media.cls.php#L1317
- plugins.trac.wordpress.org/browser/litespeed-cache/trunk/src/media.cls.php#L777
- plugins.trac.wordpress.org/changeset/3635849/litespeed-cache/trunk/src/media.cls.php
- plugins.trac.wordpress.org/changeset?old_path=%2Flitespeed-cache/tags/7.8.1&new_path=%2Flitespeed-cache/tags/7.9
- All litespeedtech CVEs on CVE Radar
- CVEs published in September 2026