Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 28 Aug 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Litespeedtech
Litespeedtech litespeed Cache Wordpress Wordpress wordpress |
|
| Vendors & Products |
Litespeedtech
Litespeedtech litespeed Cache Wordpress Wordpress wordpress |
Fri, 28 Aug 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in all versions up to, and including, 7.7. This is due to a flawed regular expression that is used to strip `width` and `height` attributes from images when the "Lazy Load Images" and "Add Missing Sizes" features are enabled. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that execute whenever a user accesses an injected page. | |
| Title | LiteSpeed Cache <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-08-28T03:39:35.416Z
Reserved: 2026-02-24T16:38:54.193Z
Link: CVE-2026-3129
No data.
Status : Received
Published: 2026-08-28T05:16:42.200
Modified: 2026-08-28T05:16:42.200
Link: CVE-2026-3129
No data.
OpenCVE Enrichment
Updated: 2026-08-28T08:15:06Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')