---
id: CVE-2025-12450
title: >-
  The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site
  Scripting via URLs in all versions up to, and including, 7.5.0.1 due to
  insufficient input sanitization and output escaping
summary: >-
  The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site
  Scripting via URLs in all versions up to, and including, 7.5.0.1 due to
  insufficient input sanitization and output escaping. This makes it possible
  for unauth…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2025-10-29'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12450'
references:
  - url: >-
      https://github.com/litespeedtech/lscache_wp/commit/3d473f44d37ec2a834162ff1d86c017e9ae67db3
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/98f71c32-9453-4598-acb5-242818508c74?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00375
epssPercentile: 0.29375
ingestedAt: '2026-10-08T11:31:27.672Z'
---

## Overview

The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 7.5.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
