<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Host.it - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/host.it/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 05:34:38 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/host.it/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-104021 Code Injection in Fastcache WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-fastcache-code-injection/</link><pubDate>Sat, 10 Oct 2026 05:34:38 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-fastcache-code-injection/</guid><description>An authenticated administrator can exploit CVE-2026-104021 in the Fastcache plugin for WordPress to inject arbitrary Apache directives into the .htaccess file, leading to remote code execution.</description><content:encoded><![CDATA[<p>CVE-2026-104021 is a critical code injection vulnerability affecting the Fastcache by Host.it plugin for WordPress, specifically in all versions up to and including 1.7.4. The vulnerability arises because the plugin registers the <code>cache_cookie_exclude</code> setting without implementing a necessary <code>sanitize_callback</code>. When the plugin builds site <code>.htaccess</code> rules via the <code>buildSiteHtaccessRules()</code> function, it only applies <code>trim()</code> to cookie values. This normalization fails to remove newline characters, allowing an authenticated administrator to inject arbitrary Apache directives. By crafting malicious input into the <code>fastcache_settings[cache_cookie_exclude][]</code> parameter, an attacker can break out of the intended capture group and append directives such as <code>php_value auto_prepend_file</code> to the <code>.htaccess</code> file. This allows for server-level configuration changes and the execution of arbitrary PHP code on every request processed by the web server.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an authenticated administrator to achieve remote code execution (RCE) on the underlying server. Since the vulnerability involves modifying the <code>.htaccess</code> file, the attacker gains the ability to manipulate server-level configurations, potentially leading to full site compromise and persistence. Organizations running WordPress with the Fastcache plugin version 1.7.4 or lower are at risk.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security and IT teams:</p>
<ul>
<li>Immediately update the Fastcache plugin to the latest version once a patch is released to resolve the sanitization logic in <code>buildSiteHtaccessRules()</code>.</li>
<li>Monitor web server access logs for requests targeting <code>wp-admin</code> that include suspicious <code>fastcache_settings</code> parameters.</li>
<li>Audit the contents of <code>.htaccess</code> files on affected WordPress instances for unauthorized entries, specifically looking for <code>php_value</code> or <code>php_flag</code> directives that were not manually configured.</li>
<li>Restrict administrative access to the WordPress dashboard to trusted IP addresses to mitigate the impact of this vulnerability, as exploitation requires authenticated administrator privileges.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>