以下是关于漏洞的关键信息: 漏洞关键信息 漏洞名称: Unauthenticated SQL Injection Vulnerability Addressed in WP Fastest Cache 1.2.2 影响插件: WP Fastest Cache 插件URL: - https://wordpress.org/plugins/wp-fastest-cache/ 作者: - https://www.wpfastestcache.com 影响版本: Versions lower than 1.2.2 CVE ID: 2023-6063 WPScan ID: 30a74105-8ade-4198-abe2-1c6f2967443e CVSS v3.1 评分: 8.6 漏洞详情 函数: of the WpFastestCacheCreateCache class is vulnerable to SQL Injection. 调用函数: createCache 代码片段 漏洞说明 The function retrieves the variable from any cookie with the text in its name, retrieving everything up to the first Due to the way the function is called and its placement within the code, an attacker can exploit a time-based blind SQL injection payload. 其他重要信息 该漏洞由 Alex Sanford 发现。 WPScan团队的协作和修正使得该问题被发现与解决。 漏洞PoC预计将在2023年11月27日公布。