An SQL injection vulnerability has been identified in the WordPress plugin “WP Fastest Cache” and could allow unauthorized users to read the contents of database .

WP Fastest Cache is a caching plugin that helps speed up page loading, improve visitor experience, and boost your website's ranking in Google. According to WordPress.org statistics, it is used by over a million sites.
What's worrying is that more than 600,000 websites are still running a vulnerable version of the plugin, which means they are exposed to potential attacks.
See also: WordPress Royal Elementor plugin: Fixes critical vulnerability
The WPScan team from Automattic has now revealed details of a vulnerability , tracked as CVE-2023-6063 and considered quite severe. It affects all versions of the WordPress plugin WP Fastest Cache prior to 1.2.2.
The vulnerability affects the 'is_user_admin' function of the 'WpFastestCacheCreateCache' class within the WP Fastest Cache plugin, which essentially checks if a user is an administrator by extracting the value “$username” from cookies.
See also: User Submitted Posts: Vulnerability found in WordPress plugin
Because the '$username' input is not sanitized, an attacker can manipulate this cookie value to change the SQL query executed by the plugin, leading to unauthorized access to the database .In this way, attackers who exploit this vulnerability in the WP Fastest Cache plugin can read the contents of a site's database. This is very dangerous, since WordPress databases usually contain sensitive information such as user data (IP addresses, emails, IDs), account passwords, plugin and theme configuration settings, and other important data for the operation of the site.
WPScan will release a proof-of-concept (PoC) exploit for the CVE-2023-6063 vulnerability on November 27, 2023. However, you should immediately update the plugin to the latest version (version 1.2.2), because the vulnerability is not complex and hackers can figure out how to exploit it.

WordPress website owners can take the following steps to protect their websites:
- Update the plugin to the latest version
- Check your website's security. Use a reputable security to scan your website for potential vulnerabilities or attacks. Look for anomalies in your website's files and settings and take action to fix them.
See also: New WordPress backdoor leads to site compromise
Importance of WordPress protection
Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.
Additionally, an unsecured WordPress site can undermine the trust and credibility you have built with customers . If their data is compromised, they are likely to take legal action against you and switch to other companies.
Securing your website is also important for maintaining the consistency and credibility of your content. If a hacker breaks into your website and corrupts the content, it can give the impression that you are not doing enough with your website.
In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining customers , preserving your company’s reputation, and staying on top of the competition.
Source: www.bleepingcomputer.com
