Threat Advisory

WP Fastest Cache Plugin Bug Exposes 600K WordPress Sites To Attacks

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

The popular WordPress caching plugin, WP Fastest Cache, has been revealed to have a critical SQL injection vulnerability, designated as CVE-2023-6063, with a severity score of 8.6. This vulnerability exposes over 600,000 websites, as per WordPress.org statistics, to potential attacks. SQL injection vulnerabilities arise when software accepts input that manipulates SQL queries, allowing unauthorized access to a site's database. In this instance, the vulnerability resides in the 'is_user_admin' function of the 'WpFastestCacheCreateCache' class within the plugin. The flaw arises from the lack of sanitization of the ' $username' input, enabling attackers to manipulate this cookie value, thereby altering the executed SQL query and gaining unauthorized access to the database. The potential consequences are severe, as WordPress databases typically contain sensitive information, including user data, account passwords, and configuration settings crucial for site functionality. The WPScan researher from Automattic plans to release a proof-of-concept (PoC) exploit for CVE-2023-6063. Despite the impending release, the vulnerability is considered straightforward, making it susceptible to exploitation by malicious actors.[/subscribe_to_unlock_form]

Summary:

The popular WordPress caching plugin, WP Fastest Cache, has been revealed to have a critical SQL injection vulnerability, designated as CVE-2023-6063, with a severity score of 8.6. This vulnerability exposes over 600,000 websites, as per WordPress.org statistics, to potential attacks. SQL injection vulnerabilities arise when software accepts input that manipulates SQL queries, allowing unauthorized access to a site's database. In this instance, the vulnerability resides in the 'is_user_admin' function of the 'WpFastestCacheCreateCache' class within the plugin. The flaw arises from the lack of sanitization of the ' $username' input, enabling attackers to manipulate this cookie value, thereby altering the executed SQL query and gaining unauthorized access to the database. The potential consequences are severe, as WordPress databases typically contain sensitive information, including user data, account passwords, and configuration settings crucial for site functionality. The WPScan researher from Automattic plans to release a proof-of-concept (PoC) exploit for CVE-2023-6063. Despite the impending release, the vulnerability is considered straightforward, making it susceptible to exploitation by malicious actors.[emaillocker id="1283"]

Recommendations:

We strongly recommend you update WP Fastest Cache to version 1.2.2

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/wp-fastest-cache-plugin-bug-exposes-600k-wordpress-sites-to-attacks/

[/emaillocker]
crossmenu