Sceawere
Vulnerability Detail
CVE-2026-104021UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Fastcache Code Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- hostspa
- Product
- Fastcache by Host.it
- Attack Type
- CWE-94 Improper Control of Generation of Code ('Code Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Fastcache by Host.it plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.7.4 via the `fastcache_settings[cache_cookie_exclude][]` parameter. This is due to the plugin registering the `cache_cookie_exclude` setting via `register_setting()` without a `sanitize_callback`, while `buildSiteHtaccessRules()` applies only `trim()` to each cookie value before interpolating it directly into an Apache `RewriteCond` line — a normalization that strips surrounding whitespace but leaves embedded newlines intact, allowing an attacker to break out of the capture group and append arbitrary directives. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary Apache directives into the site's `.htaccess` file via `file_put_contents()`, enabling server-level configuration changes such as setting `php_value auto_prepend_file` to execute attacker-controlled PHP code on every request.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-10T05:16:39.503Z",
"pubdate": "2026-10-10T05:16:39.503Z",
"executiveSummary": "The Fastcache plugin for WordPress is susceptible to an authenticated Code Injection vulnerability affecting all versions up to and including 1.7.4.\nThe vulnerability stems from improper input validation and sanitization within the 'fastcache_settings' configuration handling.\nBy manipulating the 'cache_cookie_exclude' parameter, an authenticated administrator can inject arbitrary Apache directives directly into the site's .htaccess file.\nThis vulnerability poses a critical risk as it allows for server-side code execution. By modifying the .htaccess configuration, an attacker can leverage directives such as 'php_value auto_prepend_file' to force the execution of arbitrary PHP scripts upon every server request.\nExploitation is strictly limited to authenticated users with administrative-level privileges, as the vulnerable setting resides within the plugin's administrative settings interface.\nSuccessful exploitation facilitates complete server-level configuration compromise, potentially leading to unauthorized remote code execution and persistent backdoors.",
"technicalDetails": "The root cause of this vulnerability lies in the insecure registration of the 'cache_cookie_exclude' setting via the 'register_setting()' function, which lacks an accompanying 'sanitize_callback'.\nIn the affected versions, the 'buildSiteHtaccessRules()' function is responsible for generating cache exclusion logic for the Apache web server. During this process, user-supplied input from the 'cache_cookie_exclude' array is subjected only to 'trim()' normalization.\nThe 'trim()' function is insufficient for sanitization as it only removes whitespace from the beginning and end of the string, while failing to strip newline characters or other control sequences. Consequently, an attacker can inject newline characters into the input array.\nThe attack flow proceeds as follows: An authenticated administrator provides a malicious payload containing newline characters and arbitrary Apache directives within the 'cache_cookie_exclude' field. The plugin processes these values and writes them directly into the .htaccess file using 'file_put_contents()'. Because the input is not properly escaped or validated, the injected newline characters allow the attacker to terminate the current Apache 'RewriteCond' directive and start new, unauthorized lines.\nAn attacker can leverage this primitive to inject commands such as 'php_value auto_prepend_file /path/to/malicious/code.php'. Once this directive is written to the .htaccess file, the Apache web server interprets these commands on every subsequent HTTP request. This enables the attacker to execute arbitrary PHP code in the context of the web server user.\nThis vulnerability is restricted to environments utilizing Apache, as the payload relies on the specific syntax and configuration file structure of the Apache web server. The lack of strict data validation in the plugin's configuration routine turns a seemingly minor setting into a powerful vector for persistent system compromise.\nThe vulnerability highlights the danger of direct configuration file manipulation without robust input sanitization, particularly when user-controlled data is treated as trusted input during the serialization of sensitive web server configuration files."
}