PatchSiren

hostspa CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH hostspa CVE published 2026-10-10

CVE-2026-104021

CVE-2026-104021 is a high-severity vulnerability in the Fastcache by Host.it plugin for WordPress, allowing authenticated administrators to inject arbitrary Apache directives into the site's .htaccess file. This could enable server-level configuration changes, such as executing attacker-controlled PHP code on every request. The vulnerability exists due to the plugin's improper handling of the `fastcache_s [truncated]