CVE detail
CVE-2024-28000
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 5.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- 26th August – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 26th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Halliburton, a leading U.S. oilfield services firm, was hit by a cyberattack that forced the company to take certain systems offline to contain the breach. Hackers gained access to some of the […]
vendorresearch.checkpoint.comAug 26, 2024, 12:59 PM More than five million WordPress sites are at risk of compromise due to a critical flaw in the LiteSpeed Cache plugin discovered in early August, according to researchers at Patchstack. The unauthenticated privilege escalation vulnerability, CVE-2024-28000, allows an attacker to gain administrator access and potentially upload and install malicious plugins. According to a the Patchstack […]
newswww.csoonline.comAug 23, 2024, 8:06 PMA critical vulnerability in the Litespeed Cache WordPress plugin can allow attackers to hack websites by creating an admin user.
newswww.securityweek.comAug 22, 2024, 10:01 AM📢 Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors? Through October 14th, researchers can earn up to $31,200, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest. … Read More
vendorwww.wordfence.comAug 21, 2024, 2:11 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.99 · max 0 stars
- AliHzSec/CVE-2024-28000High confidencegithubRepository topic discovery0 starsDiscovered Jul 30, 2026, 8:51 AM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-50550CVSS 8.1 · High
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a thr…
- CVE-2026-52791CVSS 2.0 · Low
fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in main.c during open(O…
- CVE-2026-17434CVSS 2.1 · Low
A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. E…
- CVE-2026-17433CVSS 1.9 · Low
A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MC…
- CVE-2026-17432CVSS 1.3 · Low
A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/a…
- CVE-2026-16764CVSS 2.1 · Low
A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such man…