Vendor
An authenticated administrator can exploit CVE-2026-104021 in the Fastcache plugin for WordPress to inject arbitrary Apache directives into the .htaccess file, leading to remote code execution.