Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a vulnerable environment with Docker and includes a Go-based brute-forcer that cracks the weak mt_rand hash to create an administrator account.
wordpress wordpress-plugin security proof-of-concept exploit poc rce vulnerability cve privilege-escalation litespeed unauthenticated cve-exploit rce-exploit wordpress-vulnerability litespeed-cache cve-2024-28000 cve-2024-28000-exploit wordpress-cve-2024-28000 unauthenticated-privilege-escalation
-
Updated
Jul 30, 2026 - Go