WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress Plugin LiteSpeed Cache 6.3.0.1及之前版本版本存在安全漏洞,该漏洞源于存在不正确的权限分配漏洞,允许权限提升。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| LiteSpeed Technologies | LiteSpeed Cache | ≤ 6.3.0.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| LiteSpeed Technologies | LiteSpeed Cache | 0 ~ 6.3.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | 0Day CVE-2024-28000 Auto Exploiter on WordPress LiteSpeed Cache plugin | https://github.com/realbotnet/CVE-2024-28000 | POC Details |
| 2 | LiteSpeed Cache Privilege Escalation PoC | https://github.com/Alucard0x1/CVE-2024-28000 | POC Details |
| 3 | LiteSpeed Cache Privilege Escalation PoC - CVE-2024-28000 | https://github.com/ebrasha/CVE-2024-28000 | POC Details |
| 4 | PoC for the CVE-2024 Litespeed Cache Privilege Escalation | https://github.com/arch1m3d/CVE-2024-28000 | POC Details |
| 5 | CVE-2024-28000 LiteSpeed Cache Privilege Escalation Scan&Exp | https://github.com/SSSSuperX/CVE-2024-28000 | POC Details |
| 6 | CVE-2024-28000 Exploit for litespeed-cache =<6.3 allows Privilege Escalation with creation of administrator account | https://github.com/JohnDoeAnonITA/CVE-2024-28000 | POC Details |
| 7 | Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from 1.9 through 6.3.0.1. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-28000.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet