{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awpfastestcachewp_fastest_cachewordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wpfastestcache:wp_fastest_cache:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2023-6063"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP Fastest Cache (\u003c= 1.2.2)"],"_cs_severities":["high"],"_cs_tags":["sqli","vulnerability","wordpress","plugin"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe WordPress plugin WP Fastest Cache, in versions 1.2.2 and earlier, is vulnerable to a time-based blind SQL injection (SQLi) attack. An unauthenticated attacker can exploit this flaw by sending specifically crafted HTTP requests containing a malicious \u003ccode\u003ewordpress_logged_in\u003c/code\u003e cookie. The injection point exists within the plugin's handling of this cookie, which fails to sanitize input before using it in database queries. By leveraging time-based SQL operators such as \u003ccode\u003eSLEEP()\u003c/code\u003e, an attacker can extract sensitive information from the \u003ccode\u003ewp_users\u003c/code\u003e table, including hashed user passwords and email addresses. A functional proof-of-concept exploit is publicly available, significantly increasing the risk of exploitation for sites running outdated versions of the plugin.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target WordPress site running WP Fastest Cache version \u0026lt;= 1.2.2.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request targeting the site, injecting SQL injection syntax into the \u003ccode\u003ewordpress_logged_in\u003c/code\u003e cookie.\u003c/li\u003e\n\u003cli\u003eThe malicious cookie payload includes a SQL \u003ccode\u003eIF\u003c/code\u003e statement and a \u003ccode\u003eSLEEP()\u003c/code\u003e command (e.g., \u003ccode\u003eAND (IF((SELECT user_pass FROM wp_users WHERE user_login=\u0026quot;admin\u0026quot;) LIKE 'a%', SLEEP(5), 0))-- -\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe plugin processes the crafted cookie and executes the injected SQL command against the WordPress backend database.\u003c/li\u003e\n\u003cli\u003eThe attacker observes the response latency of the server to confirm if the condition in the SQL statement is true (a successful guess returns a delayed response).\u003c/li\u003e\n\u003cli\u003eThe attacker iterates this process character by character to exfiltrate hashed user passwords and email addresses.\u003c/li\u003e\n\u003cli\u003eExfiltrated hashes are processed offline using tools like \u003ccode\u003ehashcat\u003c/code\u003e or \u003ccode\u003ejohn\u003c/code\u003e to recover plain-text credentials.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to bypass access controls and steal account information for registered WordPress users, including administrators. This leads to the compromise of user credentials, which can then be used to gain unauthorized administrative access to the WordPress site, leading to full site takeover, malware distribution, or further network exploitation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the WP Fastest Cache plugin to version 1.2.3 or later immediately.\u003c/li\u003e\n\u003cli\u003eIf an immediate update is not possible, disable the plugin until a patch is applied.\u003c/li\u003e\n\u003cli\u003eConfigure a Web Application Firewall (WAF) to inspect and block HTTP requests containing SQL injection patterns within the \u003ccode\u003ewordpress_logged_in\u003c/code\u003e cookie field.\u003c/li\u003e\n\u003cli\u003eReview database access logs and web server logs for suspicious requests involving repetitive delays or SQL injection characters in cookie headers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-06T06:47:07Z","date_published":"2026-09-06T06:47:07Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2023-6063-wp-fastest-cache/","summary":"WP Fastest Cache versions 1.2.2 and earlier contain a blind SQL injection vulnerability allowing unauthenticated attackers to exfiltrate sensitive user data via the wordpress_logged_in cookie.","title":"Unauthenticated Blind SQL Injection in WP Fastest Cache","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2023-6063-wp-fastest-cache/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wpfastestcache:wp_fastest_cache:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}