Impact
The vulnerability enables authenticated WordPress administrators to inject arbitrary Apache directives into the website’s .htaccess file by manipulating the cache_cookie_exclude setting. The plugin’s register_setting call lacks a sanitization callback, allowing newline characters to slip through and break the RewriteCond syntax. An attacker can then append directives such as php_value auto_prepend_file, causing the web server to execute attacker‑supplied PHP code on every request, effectively granting remote code execution access.
Affected Systems
The issue affects installations of the Fastcache by Host.it WordPress plugin up to and including version 1.7.4. Any site that has this plugin installed and has at least an administrator‑level WordPress account is vulnerable. The problem is specific to the WordPress platform and the Fastcache plugin; unrelated plugins or core WordPress components are not impacted.
Risk and Exploitability
The CVSS score of 7.2 reflects a moderate to high severity, with no EPSS score available and the vulnerability not listed in the CISA KEV catalog. Exploitation requires authenticated access at the administrator level or above, but once achieved it allows server‑level configuration changes that enable arbitrary code execution. The combination of high impact and the need for privileged credentials means that compromise of an administrator account can lead to a full site takeover.
OpenCVE Enrichment