WordPress Plugin Vulnerabilities
LiteSpeed Cache < 7.8 - Unauthenticated Stored Cross-Site Scripting via QUIC.cloud CCSS/UCSS REST API Endpoints
Description
The plugin's `/wp-json/litespeed/v1/notify_ccss` and `/wp-json/litespeed/v1/notify_ucss` REST API endpoints accept CSS content from QUIC.cloud callback notifications and store it to disk without sanitization. The stored content is later rendered inline in frontend page loads without output escaping. The access control protecting these endpoints relies on IP-based validation that can be bypassed when the WordPress site is deployed behind a reverse proxy, load balancer, or CDN with certain configurations, allowing unauthenticated attackers, under those conditions, to inject arbitrary JavaScript into CCSS/UCSS content.
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Osvaldo Noe Gonzalez Del Rio (Os)
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-05-26 (about 2 months ago)
Added
2026-05-26 (about 2 months ago)
Last Updated
2026-05-26 (about 2 months ago)