{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/fastcache--1.7.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:host.it:fastcache:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-104021"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Fastcache (\u003c= 1.7.4)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Host.it"],"content_html":"\u003cp\u003eCVE-2026-104021 is a critical code injection vulnerability affecting the Fastcache by Host.it plugin for WordPress, specifically in all versions up to and including 1.7.4. The vulnerability arises because the plugin registers the \u003ccode\u003ecache_cookie_exclude\u003c/code\u003e setting without implementing a necessary \u003ccode\u003esanitize_callback\u003c/code\u003e. When the plugin builds site \u003ccode\u003e.htaccess\u003c/code\u003e rules via the \u003ccode\u003ebuildSiteHtaccessRules()\u003c/code\u003e function, it only applies \u003ccode\u003etrim()\u003c/code\u003e to cookie values. This normalization fails to remove newline characters, allowing an authenticated administrator to inject arbitrary Apache directives. By crafting malicious input into the \u003ccode\u003efastcache_settings[cache_cookie_exclude][]\u003c/code\u003e parameter, an attacker can break out of the intended capture group and append directives such as \u003ccode\u003ephp_value auto_prepend_file\u003c/code\u003e to the \u003ccode\u003e.htaccess\u003c/code\u003e file. This allows for server-level configuration changes and the execution of arbitrary PHP code on every request processed by the web server.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an authenticated administrator to achieve remote code execution (RCE) on the underlying server. Since the vulnerability involves modifying the \u003ccode\u003e.htaccess\u003c/code\u003e file, the attacker gains the ability to manipulate server-level configurations, potentially leading to full site compromise and persistence. Organizations running WordPress with the Fastcache plugin version 1.7.4 or lower are at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Fastcache plugin to the latest version once a patch is released to resolve the sanitization logic in \u003ccode\u003ebuildSiteHtaccessRules()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for requests targeting \u003ccode\u003ewp-admin\u003c/code\u003e that include suspicious \u003ccode\u003efastcache_settings\u003c/code\u003e parameters.\u003c/li\u003e\n\u003cli\u003eAudit the contents of \u003ccode\u003e.htaccess\u003c/code\u003e files on affected WordPress instances for unauthorized entries, specifically looking for \u003ccode\u003ephp_value\u003c/code\u003e or \u003ccode\u003ephp_flag\u003c/code\u003e directives that were not manually configured.\u003c/li\u003e\n\u003cli\u003eRestrict administrative access to the WordPress dashboard to trusted IP addresses to mitigate the impact of this vulnerability, as exploitation requires authenticated administrator privileges.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T05:34:38Z","date_published":"2026-10-10T05:34:38Z","id":"https://feed.craftedsignal.io/briefs/2026-10-fastcache-code-injection/","summary":"An authenticated administrator can exploit CVE-2026-104021 in the Fastcache plugin for WordPress to inject arbitrary Apache directives into the .htaccess file, leading to remote code execution.","title":"CVE-2026-104021 Code Injection in Fastcache WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-fastcache-code-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Fastcache (\u003c= 1.7.4)","version":"https://jsonfeed.org/version/1.1"}