PatchSiren cyber security CVE debrief
CVE-2026-104021 hostspa CVE debrief
CVE-2026-104021 is a high-severity vulnerability in the Fastcache by Host.it plugin for WordPress, allowing authenticated administrators to inject arbitrary Apache directives into the site's .htaccess file. This could enable server-level configuration changes, such as executing attacker-controlled PHP code on every request. The vulnerability exists due to the plugin's improper handling of the `fastcache_settings[cache_cookie_exclude][]` parameter, which allows an attacker to break out of the capture group and append arbitrary directives. Administrators of WordPress installations using the Fastcache by Host.it plugin should be aware of this vulnerability and take steps to mitigate,
- Vendor
- hostspa
- Product
- Fastcache by Host.it
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Administrators of WordPress installations using the Fastcache by Host.it plugin should be aware of this vulnerability and take steps to mitigate. They should verify their version and update to a patched version if available. They should also review their .htaccess files for any suspicious changes and monitor server logs for unusual activity. Additionally, they should confirm whether affected product deployments exist in managed environments and assign an
Why it matters
CVE-2026-104021 is a high-severity vulnerability in the Fastcache by Host.it plugin for WordPress, allowing authenticated administrators to inject arbitrary Apache directives into the site's .htaccess file. This could enable server-level configuration changes, such as executing attacker-controlled PHP code on every request.
- Potential for server-level configuration changes
- Possible execution of attacker-controlled PHP code on every request
- Ability to inject arbitrary Apache directives into .htaccess files
Technical summary
The Fastcache by Host.it plugin for WordPress is vulnerable to code injection in versions up to and including 1.7.4. An authenticated attacker with administrator-level access can inject arbitrary Apache directives into the site's .htaccess file via the `fastcache_settings[cache_cookie_exclude][]` parameter. This is due to the plugin registering the `cache_cookie_exclude` setting via `register_setting()` without a `sanitize_callback`, while `buildSiteHtaccessRules()` applies only `trim()` to each cookie value before interpolating it directly into an Apache `RewriteCond` line — a normalization that strips surrounding whitespace but leaves embedded newlines intact, allowing an attacker to break out of the capture
Defensive priority
Administrators of WordPress installations using the Fastcache by Host.it plugin should verify their version and update to a patched version if available. They should also review their .htaccess files for any suspicious changes.
Recommended defensive actions
- Verify the version of the Fastcache by Host.it plugin and update to a patched version if available.
- Review .htaccess files for any suspicious changes.
- Monitor server logs for unusual activity.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The vulnerability exists in versions up to and including 1.7.4 of the Fastcache by Host.it plugin. An attacker with administrator-level access can inject arbitrary Apache directives via the `fastcache_settings[cache_cookie_exclude][]` parameter.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104021 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104021
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104021 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104021
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Fastcache by Host.it <= 1.7.4 - Authenticated (Administrator+) Code Injection via .htaccess Dire
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104021.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/fastcache-by-host-it/tags/1.7.4/src/Core/Platform/Utility.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/fastcache-by-host-it/tags/1.7.4/src/Dispatcher.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/fastcache-by-host-it/tags/1.7.4/src/Admin.php
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.