CVE-2026-104021 Code Injection in Fastcache WordPress Plugin
An authenticated administrator can exploit CVE-2026-104021 in the Fastcache plugin for WordPress to inject arbitrary Apache directives into the .htaccess file, leading to remote code execution.
CVE search metadata
CVE search record: CVE-2026-104021. Severity: high. CVSS: 7.2. KEV: no. Product: Fastcache (<= 1.7.4). Brief: CVE-2026-104021 Code Injection in Fastcache WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-fastcache-code-injection/
CVE-2026-104021 is a critical code injection vulnerability affecting the Fastcache by Host.it plugin for WordPress, specifically in all versions up to and including 1.7.4. The vulnerability arises because the plugin registers the cache_cookie_exclude setting without implementing a necessary sanitize_callback. When the plugin builds site .htaccess rules via the buildSiteHtaccessRules() function, it only applies trim() to cookie values. This normalization fails to remove newline characters, allowing an authenticated administrator to inject arbitrary Apache directives. By crafting malicious input into the fastcache_settings[cache_cookie_exclude][] parameter, an attacker can break out of the intended capture group and append directives such as php_value auto_prepend_file to the .htaccess file. This allows for server-level configuration changes and the execution of arbitrary PHP code on every request processed by the web server.
Impact
Successful exploitation of this vulnerability allows an authenticated administrator to achieve remote code execution (RCE) on the underlying server. Since the vulnerability involves modifying the .htaccess file, the attacker gains the ability to manipulate server-level configurations, potentially leading to full site compromise and persistence. Organizations running WordPress with the Fastcache plugin version 1.7.4 or lower are at risk.
Recommendation
Prioritized actions for security and IT teams:
- Immediately update the Fastcache plugin to the latest version once a patch is released to resolve the sanitization logic in
buildSiteHtaccessRules(). - Monitor web server access logs for requests targeting
wp-adminthat include suspiciousfastcache_settingsparameters. - Audit the contents of
.htaccessfiles on affected WordPress instances for unauthorized entries, specifically looking forphp_valueorphp_flagdirectives that were not manually configured. - Restrict administrative access to the WordPress dashboard to trusted IP addresses to mitigate the impact of this vulnerability, as exploitation requires authenticated administrator privileges.
Immediate actions
Audit WordPress installations for Fastcache plugin version 1.7.4 or lower
Mitigations
Upgrade Fastcache to the latest available patched version
CVE-2026-104021
Detection coverage 1
Detect CVE-2026-104021 Exploitation - Apache Directive Injection in .htaccess
highDetects exploitation of CVE-2026-104021 by identifying HTTP POST requests to WordPress containing shell-related directives in the Fastcache settings parameter.
Detection queries are available on the platform. Get full rules →