The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from servers, allowing attackers to make requests to certain endpoints by using a specific X-Forwarded-For header value. In addition, one of the

