WordPress · Litespeed Cache · CVE-2025-12450
**Name of the Vulnerable Software and Affected Versions**
LiteSpeed Cache plugin for WordPress versions up to and including 7.5.0.1
**Description**
The LiteSpeed Cache plugin for WordPress is susceptible to Reflected Cross-Site Scripting through URLs. This is caused by inadequate input sanitization and output escaping. An unauthenticated attacker can inject arbitrary web scripts into pages, which will execute if a user is tricked into performing an action, such as clicking a link.
**Recommendations**
Update the LiteSpeed Cache plugin to a version newer than 7.5.0.1.