The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in all versions up to, and including, 7.7. This is due to a flawed regular expression that is used to strip `width` and `height` attributes from images when the "Lazy Load Images" and "Add Missing Sizes" features are enabled. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that execute whenever a user accesses an injected page.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 28 Aug 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Litespeedtech
Litespeedtech litespeed Cache Wordpress Wordpress wordpress |
|
| Vendors & Products |
Litespeedtech
Litespeedtech litespeed Cache Wordpress Wordpress wordpress |
Fri, 28 Aug 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in all versions up to, and including, 7.7. This is due to a flawed regular expression that is used to strip `width` and `height` attributes from images when the "Lazy Load Images" and "Add Missing Sizes" features are enabled. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that execute whenever a user accesses an injected page. | |
| Title | LiteSpeed Cache <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-08-28T03:39:35.416Z
Reserved: 2026-02-24T16:38:54.193Z
Link: CVE-2026-3129
No data.
Status : Deferred
Published: 2026-08-28T05:16:42.200
Modified: 2026-08-28T15:09:00.790
Link: CVE-2026-3129
No data.
OpenCVE Enrichment
Updated: 2026-08-28T15:30:08Z
Weaknesses