CVE-2026-18978: stored cross-site scripting in litespeedtech LiteSpeed Cache

An attacker can inject persistent JavaScript into pages served by the LiteSpeed Cache WordPress plugin, allowing scripts to run in visitors' browsers (CVE-2026-18978). Versions 7.8.1 and earlier in the 7.x branch are affected. Exploitation requires the site to permit users with previously approved comments to post new comments and have the require_name_email setting disabled, which lets a specially crafted comment bypass sanitization and reach the vulnerable output path.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.2HIGH
EPSS
0.00368
CWE
CWE-79
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as urgent: there is no vendor patch available and the flaw enables stored XSS that executes in site visitors' browsers, increasing the risk to users and site sessions.

What is CVE-2026-18978?

An attacker can inject persistent JavaScript into pages served by the LiteSpeed Cache WordPress plugin, allowing scripts to run in visitors' browsers (CVE-2026-18978). Versions 7.8.1 and earlier in the 7.x branch are affected. Exploitation requires the site to permit users with previously approved comments to post new comments and have the require_name_email setting disabled, which lets a specially crafted comment bypass sanitization and reach the vulnerable output path. The weakness is classified as CWE-79 (Cross-site Scripting).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Which versions of litespeedtech LiteSpeed Cache are affected?

BRANCHAFFECTEDFIXED
7.x7.8.1 and earlier

Is CVE-2026-18978 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-18978

  1. Disable or restrict the comment feature until a vendor fix is released.
  2. Enable require_name_email and tighten comment moderation to prevent new unvetted posts.
  3. Apply strict input sanitization or remove allowed elements that permit numeric character references in comments.
  4. Monitor web logs and page content for unexpected script injections and follow vendor guidance when published.

Frequently asked questions

Is CVE-2026-18978 being actively exploited?

There are no public reports of active exploitation of CVE-2026-18978 as of 2026-09-29.

Which LiteSpeed Cache versions are affected by CVE-2026-18978?

LiteSpeed Cache versions 7.8.1 and earlier in the 7.x branch are listed as affected.

Is there a patch for CVE-2026-18978?

No patch is available according to the known facts; vendors have not listed fixed versions.

Does CVE-2026-18978 require authentication?

Exploitation depends on site comment settings: it requires that users with previously approved comments can post new comments and that require_name_email is disabled, rather than a standard authenticated account.

References