PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104021 hostspa CVE debrief

CVE-2026-104021 is a high-severity vulnerability in the Fastcache by Host.it plugin for WordPress, allowing authenticated administrators to inject arbitrary Apache directives into the site's .htaccess file. This could enable server-level configuration changes, such as executing attacker-controlled PHP code on every request. The vulnerability exists due to the plugin's improper handling of the `fastcache_settings[cache_cookie_exclude][]` parameter, which allows an attacker to break out of the capture group and append arbitrary directives. Administrators of WordPress installations using the Fastcache by Host.it plugin should be aware of this vulnerability and take steps to mitigate,

Vendor
hostspa
Product
Fastcache by Host.it
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Administrators of WordPress installations using the Fastcache by Host.it plugin should be aware of this vulnerability and take steps to mitigate. They should verify their version and update to a patched version if available. They should also review their .htaccess files for any suspicious changes and monitor server logs for unusual activity. Additionally, they should confirm whether affected product deployments exist in managed environments and assign an

Why it matters

CVE-2026-104021 is a high-severity vulnerability in the Fastcache by Host.it plugin for WordPress, allowing authenticated administrators to inject arbitrary Apache directives into the site's .htaccess file. This could enable server-level configuration changes, such as executing attacker-controlled PHP code on every request.

  • Potential for server-level configuration changes
  • Possible execution of attacker-controlled PHP code on every request
  • Ability to inject arbitrary Apache directives into .htaccess files

Technical summary

The Fastcache by Host.it plugin for WordPress is vulnerable to code injection in versions up to and including 1.7.4. An authenticated attacker with administrator-level access can inject arbitrary Apache directives into the site's .htaccess file via the `fastcache_settings[cache_cookie_exclude][]` parameter. This is due to the plugin registering the `cache_cookie_exclude` setting via `register_setting()` without a `sanitize_callback`, while `buildSiteHtaccessRules()` applies only `trim()` to each cookie value before interpolating it directly into an Apache `RewriteCond` line — a normalization that strips surrounding whitespace but leaves embedded newlines intact, allowing an attacker to break out of the capture

Defensive priority

Administrators of WordPress installations using the Fastcache by Host.it plugin should verify their version and update to a patched version if available. They should also review their .htaccess files for any suspicious changes.

Recommended defensive actions

  • Verify the version of the Fastcache by Host.it plugin and update to a patched version if available.
  • Review .htaccess files for any suspicious changes.
  • Monitor server logs for unusual activity.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The vulnerability exists in versions up to and including 1.7.4 of the Fastcache by Host.it plugin. An attacker with administrator-level access can inject arbitrary Apache directives via the `fastcache_settings[cache_cookie_exclude][]` parameter.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104021 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104021

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104021 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104021

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Fastcache by Host.it <= 1.7.4 - Authenticated (Administrator+) Code Injection via .htaccess Dire

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104021.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/fastcache-by-host-it/tags/1.7.4/src/Core/Platform/Utility.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/fastcache-by-host-it/tags/1.7.4/src/Dispatcher.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/fastcache-by-host-it/tags/1.7.4/src/Admin.php

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.