Feed/CVE-2024-28000
CVE-2024-28000CRITICALCVSS 9.8

CVE-2024-28000

Published Aug 21, 2024·Updated Jun 17, 2026

NVD Description

Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.

Public Exploits & PoCs8 found

PoC: CVE-2024-28000

CVE-2024-28000 LiteSpeed Cache Privilege Escalation Scan&Exp

1

PoC: CVE-2024-28000

LiteSpeed Cache Privilege Escalation PoC

1

[POC] GHSA-3whf-vgf2-9w6g — CVE-2024-28000

Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a vulnerable environment with Docker and includes a Go-based brute-forcer that cracks the weak mt_rand hash to create an administrator account.

PoC: CVE-2024-28000-Exploit-Lab

Hands-on reproduction of CVE-2024-28000 in LiteSpeed Cache using an isolated WordPress lab. Includes reconnaissance, vulnerable hash recovery, Administrator privilege escalation proof, cleanup, and remediation-focused documentation.

PoC: CVE-2024-28000

CVE-2024-28000 Exploit for litespeed-cache =<6.3 allows Privilege Escalation with creation of administrator account

PoC: CVE-2024-28000

PoC for the CVE-2024 Litespeed Cache Privilege Escalation

PoC: CVE-2024-28000

LiteSpeed Cache Privilege Escalation PoC - CVE-2024-28000

PoC: CVE-2024-28000

0Day CVE-2024-28000 Auto Exploiter on WordPress LiteSpeed Cache plugin

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free