Skip to content
Threat Feed
high advisory

CVE-2026-104021 Code Injection in Fastcache WordPress Plugin

An authenticated administrator can exploit CVE-2026-104021 in the Fastcache plugin for WordPress to inject arbitrary Apache directives into the .htaccess file, leading to remote code execution.

CVE search metadata

CVE search record: CVE-2026-104021. Severity: high. CVSS: 7.2. KEV: no. Product: Fastcache (<= 1.7.4). Brief: CVE-2026-104021 Code Injection in Fastcache WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-fastcache-code-injection/

CVE-2026-104021 is a critical code injection vulnerability affecting the Fastcache by Host.it plugin for WordPress, specifically in all versions up to and including 1.7.4. The vulnerability arises because the plugin registers the cache_cookie_exclude setting without implementing a necessary sanitize_callback. When the plugin builds site .htaccess rules via the buildSiteHtaccessRules() function, it only applies trim() to cookie values. This normalization fails to remove newline characters, allowing an authenticated administrator to inject arbitrary Apache directives. By crafting malicious input into the fastcache_settings[cache_cookie_exclude][] parameter, an attacker can break out of the intended capture group and append directives such as php_value auto_prepend_file to the .htaccess file. This allows for server-level configuration changes and the execution of arbitrary PHP code on every request processed by the web server.

Impact

Successful exploitation of this vulnerability allows an authenticated administrator to achieve remote code execution (RCE) on the underlying server. Since the vulnerability involves modifying the .htaccess file, the attacker gains the ability to manipulate server-level configurations, potentially leading to full site compromise and persistence. Organizations running WordPress with the Fastcache plugin version 1.7.4 or lower are at risk.

Recommendation

Prioritized actions for security and IT teams:

  • Immediately update the Fastcache plugin to the latest version once a patch is released to resolve the sanitization logic in buildSiteHtaccessRules().
  • Monitor web server access logs for requests targeting wp-admin that include suspicious fastcache_settings parameters.
  • Audit the contents of .htaccess files on affected WordPress instances for unauthorized entries, specifically looking for php_value or php_flag directives that were not manually configured.
  • Restrict administrative access to the WordPress dashboard to trusted IP addresses to mitigate the impact of this vulnerability, as exploitation requires authenticated administrator privileges.

Immediate actions

Audit WordPress installations for Fastcache plugin version 1.7.4 or lower

IT Operations 24h

Mitigations

Upgrade Fastcache to the latest available patched version

immediate IT Operations

CVE-2026-104021

Detection coverage 1

Detect CVE-2026-104021 Exploitation - Apache Directive Injection in .htaccess

high

Detects exploitation of CVE-2026-104021 by identifying HTTP POST requests to WordPress containing shell-related directives in the Fastcache settings parameter.

sigma tactics: execution, initial_access, persistence techniques: T1059.003 sources: webserver

Detection queries are available on the platform. Get full rules →