Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-02 ยท updated: 2026-09-02 ยท tags: [cve, code-execution, wordpress, government, actively-exploited] ยท confidence: high ยท severity: high ยท affected_sectors: [technology, government] ยท au_impact: true

CVE-2024-2800

Summary

CVE-2024-2800 is a LiteSpeed Cache WordPress plugin vulnerability that was patched in August 2024. Despite being fixed more than two years ago, it was still exploited by a Chinese-speaking operator against a Philippines nuclear agency and a marine engineering/shipbuilding company serving the Philippine Navy.

Details

Threat-hunting firm Hunt.io documented a Chinese-speaking operator using both an ownCloud vulnerability (CVE-2023-49105) and LiteSpeed Cache WordPress CVE-2024-2800 to compromise Philippine targets, even though both were patched more than two years earlier. The LiteSpeed Cache flaw enabled access that contributed to the theft of reactor core-component databases, historical fuel inventories, radiation-safety manuals and personnel records. The exploit's persistence illustrates that unpatchable or unpatched internet-facing collaboration software is a common initial-access failure.

Remediation

WordPress sites running the LiteSpeed Cache plugin should apply the August 2024 patch if not already installed. The incident underscores the value of continuously patching internet-facing web plugins even after disclosure.

Source