CVE-2024-44000 is an insufficiently protected credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache that can lead to authentication bypass. The issue affects LiteSpeed Cache versions prior to 6.5.0.1. Available information indicates the flaw stems from inadequate protection of credential-related material, enabling an attacker to bypass normal authentication controls under affected conditions. Specific vulnerable functions and code paths are not currently available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module (wp_litespeed_cookie_theft.rb) that exploits CVE-2024-44000, an unauthenticated account takeover vulnerability in the LiteSpeed Cache WordPress plugin (versions prior to 6.5.0.1). The exploit targets sites where the plugin's Debug Logging feature is enabled, causing admin cookies to be written to /wp-content/debug.log, which is accessible without authentication. The module retrieves these cookies, verifies their validity by accessing /wp-admin/, and, if successful, uses them to upload and execute a malicious plugin (payload) on the server. The exploit supports PHP, Unix, and Windows payloads, and is fully weaponized as part of the Metasploit framework. The code is well-structured, with clear separation of logic for cookie extraction, verification, and payload delivery. The main attack vector is network-based, exploiting HTTP endpoints exposed by the vulnerable WordPress installation.
This repository contains a Python proof-of-concept exploit (GenCookieSessionHijack.py) targeting CVE-2024-44000, a vulnerability in WordPress sites where debug logs are publicly accessible and may contain active session cookies. The exploit automates the process of downloading the debug log from each target URL, extracting any session cookies (specifically those matching the 'wordpress_logged_in_*' pattern), and attempting to use them to hijack an admin session. If successful, it generates a URL that allows the attacker to access the WordPress admin dashboard as the hijacked user and can open this session in the attacker's browser. The repository includes a README with detailed usage instructions, a requirements.txt for dependencies (requests, argparse, urllib3), and an MIT license. The main entry point is GenCookieSessionHijack.py, which is a standalone script requiring a list of target URLs. The exploit is a POC and does not include advanced payloads or customization, but demonstrates the risk of exposed debug logs on WordPress sites.
This repository contains a Python exploit script (CVE-2024-44000.py) targeting CVE-2024-44000, a vulnerability in the LiteSpeed Cache WordPress plugin. The exploit automates the process of accessing publicly exposed debug log files (wp-content/debug.log) on WordPress sites, extracting session cookies (including those of admin users), and attempting to hijack those sessions by setting the cookies in a browser session. The script processes a list of target URLs, checks for accessible debug logs, parses out session cookies, and tries to access the admin panel as the compromised user. If successful, it provides URLs for browser-based access to the hijacked session. The repository also includes a README.md with usage instructions, dorking tips for finding vulnerable sites, and a disclaimer. The exploit is operational and demonstrates a real-world attack scenario, but requires the target to have an exposed debug log file.
This repository contains a proof-of-concept (PoC) exploit for CVE-2024-44000, a vulnerability in the LiteSpeed Cache WordPress plugin. The main file, CVE_2024_44000.py, is a Python script that automates the process of extracting session cookies from a publicly accessible debug log file (wp-content/debug.log) on a vulnerable WordPress site. The script then attempts to use these cookies to hijack an authenticated session, potentially granting the attacker admin access to the WordPress dashboard. The exploit relies on the debug log being both accessible and containing valid session cookies, which may not always be the case. The repository also includes a README.md with a detailed explanation of the exploit steps, a LICENSE file, and a .gitignore. The exploit is network-based, targeting web-accessible endpoints, and is intended for educational and testing purposes only.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.