QID 150749
Date Published: 2023-11-28
QID 150749: WordPress WP Fastest Cache Plugin: SQL Injection Vulnerability (CVE-2023-6063)
WP Fastest Cache is a WordPress plugin. Its not only a wp cache plugin but also a speed optimization WordPress cache plugin.
The WP Fastest Cache plugin for WordPress has a security issue that allows attackers to perform SQL Injection. This occurs because the plugin does not properly handle the '$username' variable from user cookies, lacking necessary precautions in the SQL query. As a result, unauthorized attackers can add extra SQL queries to the existing ones, potentially extracting sensitive data from the database.
Affected Versions:
WP Fastest Cache versions up to and including 1.2.2
QID Detection Logic:
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.
An unauthorized attacker could use this weakness to get into the system, access the database, take sensitive information, and control the database by making changes or deletions using SQL commands.
- WP Fastest Cache -
wordpress.org/plugins/wp-fastest-cache/#developers
CVEs related to QID 150749
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WP Fastest Cache |
|