Where
-Infinity
0
Severity
6.4
XSS
AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted <img> tag attributes in all versions up to, and including, 7.7. This is due to a flawed regular expression that is used to strip width and height attributes from images when the "Lazy Load Images" and "Add Missing Sizes" features are enabled. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that execute whenever a user accesses an injected page.

First published (updated )
Severity
5.5
EPSS
0.04%
XSS
AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up to, and including, 6.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfilteredhtml has been disabled.

First published (updated )

Hunt.io reseachers discovered an open directory staging the tooling and stolen data from an intrusion into two Philippine organizations, a nuclear research agency and a marine engineering company that contracts with the Navy. Nothing exotic was needed to get in.

ownCloud compromised via CVE-2023-49105 (patched in 2023), abusing an empty signing secret that is the default on new installs Naval contractor hit via CVE-2024-28000 (LiteSpeed Cache, patched Aug 2024) and an XML-RPC brute force using the rockyou.txt wordlist 176 files (\~372 MB) recovered including reactor core component databases, radiation safety docs, employee PII, and credential stores. A CSV referenced \~9 GB actually exfiltrated Simplified Chinese throughout the operator's scripts, logs, and folder names A separate, possibly unrelated EtherHiding compromise was also active on the same WordPress site, 174 IPs found with the same loader

Patch internet-facing collaboration software, set a real signing key on ownCloud, disable XML-RPC if you don't use it, and enforce MFA on admin accounts.

Full research, IOCs, and MITRE mapping:

https://hunt.io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor

First published (updated )
Social
reddit

The Hunt.io research team found an open directory staging the full toolkit behind an intrusion into a Philippine nuclear research agency and a naval contractor. The ownCloud path is the interesting part technically.

CVE-2023-49105 lets you forge pre-signed WebDAV URLs when the signing secret is empty, which is the default state on a fresh install. Five custom Python scripts on the server implement this: the signing routine passes an empty bytes literal as the PBKDF2 salt, sets OC-Credential to the account being impersonated, and issues GET requests against /remote.php/dav/files/<account>/<path>, receiving files as that user with no credentials. Four scripts target one account each, the fifth adds PROPFIND enumeration with Depth: 1 to walk folders that were not pre-enumerated.

The naval contractor was hit separately via CVE-2024-28000 (LiteSpeed Cache) using a custom Go reimplementation of MT19937 with PHP mt\rand() parity, verified against 11 known seed/output pairs, plus an XML-RPC brute force with rockyou.txt. Both produced unauthorized access independently.

We also found a separate, possibly unrelated EtherHiding compromise on the same WordPress site. A HuntSQL query on the smart contract address returned 174 unique IPs hosting likely compromised pages with the same NoChain loader strings.

Full writeup with IOCs, the signing routine, and MITRE mapping: https://hunt.io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor

First published (updated )
Social
reddit

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203