CVE-2024-2800
Summary
CVE-2024-2800 is a LiteSpeed Cache WordPress plugin vulnerability that was patched in August 2024. Despite being fixed more than two years ago, it was still exploited by a Chinese-speaking operator against a Philippines nuclear agency and a marine engineering/shipbuilding company serving the Philippine Navy.
Details
Threat-hunting firm Hunt.io documented a Chinese-speaking operator using both an ownCloud vulnerability (CVE-2023-49105) and LiteSpeed Cache WordPress CVE-2024-2800 to compromise Philippine targets, even though both were patched more than two years earlier. The LiteSpeed Cache flaw enabled access that contributed to the theft of reactor core-component databases, historical fuel inventories, radiation-safety manuals and personnel records. The exploit's persistence illustrates that unpatchable or unpatched internet-facing collaboration software is a common initial-access failure.
Remediation
WordPress sites running the LiteSpeed Cache plugin should apply the August 2024 patch if not already installed. The incident underscores the value of continuously patching internet-facing web plugins even after disclosure.