WordPress Plugin Vulnerabilities

LiteSpeed Cache < 7.8 - Unauthenticated Stored Cross-Site Scripting via QUIC.cloud CCSS/UCSS REST API Endpoints

Description

The plugin's `/wp-json/litespeed/v1/notify_ccss` and `/wp-json/litespeed/v1/notify_ucss` REST API endpoints accept CSS content from QUIC.cloud callback notifications and store it to disk without sanitization. The stored content is later rendered inline in frontend page loads without output escaping. The access control protecting these endpoints relies on IP-based validation that can be bypassed when the WordPress site is deployed behind a reverse proxy, load balancer, or CDN with certain configurations, allowing unauthenticated attackers, under those conditions, to inject arbitrary JavaScript into CCSS/UCSS content.

Affects Plugins

Fixed in 7.8

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Osvaldo Noe Gonzalez Del Rio (Os)
Verified
No

Timeline

Publicly Published
2026-05-26 (about 2 months ago)
Added
2026-05-26 (about 2 months ago)
Last Updated
2026-05-26 (about 2 months ago)

Other