A critical unauthenticated SQL injection vulnerability exists in the WP Fastest Cache WordPress plugin prior to version 1.2.2. The vulnerability arises from improper sanitization and escaping of the $username variable in the is_user_admin function of the WpFastestCacheCreateCache class. This variable, extracted from cookies, is used directly in an SQL query before input sanitization occurs, allowing attackers to inject arbitrary SQL. The flaw is exploitable via time-based blind SQL injection techniques, enabling attackers to read the full contents of the WordPress database without authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This three-file Python PoC targets CVE-2023-6063 in WP Fastest Cache 1.2.2 and earlier. poc.py is the sole executable component; it uses requests for HTTP traffic and pwntools logging/progress output, while requirements.txt lists those dependencies and README.md documents use and mitigation. The script places conditional MySQL SQL expressions in the wordpress_logged_in cookie and measures request latency to determine whether each condition caused SLEEP(delay). It supports checking a username, validating a supplied password hash or email domain, extracting a selected user's wp_users.user_pass hash, and extracting wp_users.user_email. Extraction iterates a printable-character alphabet and tests each database character position until a matching delayed response is observed. The target address is entirely operator-supplied; the repository contains no hard-coded external host, IP address, or command-and-control endpoint.
This repository provides a Python proof-of-concept exploit for CVE-2023-6063, a time-based blind SQL injection vulnerability in the WP Fastest Cache WordPress plugin (versions <=1.2.2). The exploit is implemented in 'poc.py', which uses the 'requests' and 'pwntools' libraries to automate the injection of SQL payloads via the 'wordpress_logged_in' cookie. The script allows an attacker to extract hashed passwords and email addresses for WordPress users by measuring response delays caused by the SLEEP() function in SQL queries. The exploit is unauthenticated and works remotely, requiring only the target URL and a valid username. The repository includes a README.md with detailed usage instructions, technical background, and mitigation advice, as well as a requirements.txt listing dependencies. The main entry point is 'poc.py', which provides command-line options for customizing the attack. No hardcoded endpoints are present, but the script is designed to target arbitrary WordPress sites running the vulnerable plugin.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.