CVE WATCH / VULNERABILITY DETAIL

CVE-2026-104021

HIGHCVSS 7.2NVD feed

Published 10 October 2026 · tracked since 10 October 2026

Description

The Fastcache by Host.it plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.7.4 via the `fastcache_settings[cache_cookie_exclude][]` parameter. This is due to the plugin registering the `cache_cookie_exclude` setting via `register_setting()` without a `sanit

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-104021 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-104021

HIGHCVSS 7.2NVD feed

Published 10 October 2026 · tracked since 10 October 2026

Description

The Fastcache by Host.it plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.7.4 via the `fastcache_settings[cache_cookie_exclude][]` parameter. This is due to the plugin registering the `cache_cookie_exclude` setting via `register_setting()` without a `sanit

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]