Description
The Fastcache by Host.it plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.7.4 via the `fastcache_settings[cache_cookie_exclude][]` parameter. This is due to the plugin registering the `cache_cookie_exclude` setting via `register_setting()` without a `sanitize_callback`, while `buildSiteHtaccessRules()` applies only `trim()` to each cookie value before interpolating it directly into an Apache `RewriteCond` line — a normalization that strips surrounding whitespace but leaves embedded newlines intact, allowing an attacker to break out of the capture group and append arbitrary directives. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary Apache directives into the site's `.htaccess` file via `file_put_contents()`, enabling server-level configuration changes such as setting `php_value auto_prepend_file` to execute attacker-controlled PHP code on every request.
Published: 2026-10-10
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Server configuration tampering leading to remote code execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability enables authenticated WordPress administrators to inject arbitrary Apache directives into the website’s .htaccess file by manipulating the cache_cookie_exclude setting. The plugin’s register_setting call lacks a sanitization callback, allowing newline characters to slip through and break the RewriteCond syntax. An attacker can then append directives such as php_value auto_prepend_file, causing the web server to execute attacker‑supplied PHP code on every request, effectively granting remote code execution access.

Affected Systems

The issue affects installations of the Fastcache by Host.it WordPress plugin up to and including version 1.7.4. Any site that has this plugin installed and has at least an administrator‑level WordPress account is vulnerable. The problem is specific to the WordPress platform and the Fastcache plugin; unrelated plugins or core WordPress components are not impacted.

Risk and Exploitability

The CVSS score of 7.2 reflects a moderate to high severity, with no EPSS score available and the vulnerability not listed in the CISA KEV catalog. Exploitation requires authenticated access at the administrator level or above, but once achieved it allows server‑level configuration changes that enable arbitrary code execution. The combination of high impact and the need for privileged credentials means that compromise of an administrator account can lead to a full site takeover.

Generated by OpenCVE AI on October 10, 2026 at 05:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Fastcache by Host.it to the latest version (≥1.7.5) where the cache_cookie_exclude setting is properly sanitized.
  • Restrict write permissions on the site’s .htaccess file so that only the web server or site owner can modify it.
  • Review the .htaccess file for unexpected Apache directives and remove any that were added inadvertently; if a patch cannot be applied immediately, consider disabling the cache_cookie_exclude feature or uninstalling the plugin until an update is available.

Generated by OpenCVE AI on October 10, 2026 at 05:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description The Fastcache by Host.it plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.7.4 via the `fastcache_settings[cache_cookie_exclude][]` parameter. This is due to the plugin registering the `cache_cookie_exclude` setting via `register_setting()` without a `sanitize_callback`, while `buildSiteHtaccessRules()` applies only `trim()` to each cookie value before interpolating it directly into an Apache `RewriteCond` line — a normalization that strips surrounding whitespace but leaves embedded newlines intact, allowing an attacker to break out of the capture group and append arbitrary directives. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary Apache directives into the site's `.htaccess` file via `file_put_contents()`, enabling server-level configuration changes such as setting `php_value auto_prepend_file` to execute attacker-controlled PHP code on every request.
Title Fastcache by Host.it <= 1.7.4 - Authenticated (Administrator+) Code Injection via .htaccess Directive Injection via 'cache_cookie_exclude' Setting
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T04:26:48.359Z

Reserved: 2026-10-01T17:00:05.312Z

Link: CVE-2026-104021

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T05:16:39.503

Modified: 2026-10-10T05:16:39.503

Link: CVE-2026-104021

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T05:30:09Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')