Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-29 ยท updated: 2026-08-29 ยท tags: [cve, liteloader, privilege-escalation, exploit-lite] ยท confidence: high ยท severity: high ยท affected_sectors: [technology, government, defence] ยท au_impact: true

CVE-2024-28000

CVE-2024-28000 is a privilege-escalation vulnerability in the LiteSpeed Cache WordPress plugin. In the August 2026 context it was one of two years-old, known flaws weaponised by a suspected Chinese-speaking espionage operator against Philippine targets โ€” alongside the ownCloud authentication bypass CVE-2023-49105.

Attribute Detail
CVE CVE-2024-28000
Type Privilege escalation
Product LiteSpeed Cache (WordPress plugin)
Exploitation case Weaponised against Philippine nuclear research agency + marine engineering/shipbuilding contractor (Aug 2026)
Notable Years-old, previously patched flaw โ€” used as an illustration of the supply-chain/patch-lag problem
Source Hunt.io (via digest) โ€” Tier 2/4

The Philippine campaigns exfiltrated nuclear-material accounts, research-reactor core-component databases, personnel records and encrypted credential stores (KeePass, BitLocker recovery keys). Hunt.io recovered ~9 GB of nuclear-agency data staged on an exposed attacker server. The reuse of a known, older CVE underscores that unpatched legacy flaws remain a first-order espionage vector.

Source