CVE-2026-104021 | hostspa Fastcache by Host.it Plugin up to 1.7.4 on WordPress Cache Cookie Exclusion buildSiteHtaccessRules fastcache_settings[cache_cookie_exclude][] code injection
A vulnerability categorized as problematic has been discovered in hostspa Fastcache by Host.it Plugin up to 1.7.4 on WordPress. This issue affects the function buildSiteHtaccessRules of the component Cache Cookie Exclusion. The manipulation of the argument fastcache_settings[cache_cookie_exclude][] results in code injection.
This vulnerability is identified as CVE-2026-104021. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More