PT-2026-7851 · WordPress · Wordpress+1

Athiwat Tiprasaharn

+2

·

Publicado

2026-02-12

·

Atualizado

2026-02-12

·

CVE-2026-1104

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FastDup – Fastest WordPress Migration & Duplicator plugin versions up to 2.7.1
Description The FastDup plugin for WordPress is affected by a flaw that allows unauthorized backup creation and download. This is due to a missing capability check on REST API endpoints. Authenticated attackers with Contributor-level access or higher can create and download full-site backup archives, including database exports and configuration files. The affected API endpoints are not explicitly specified, but the issue relates to REST API functionality. The vulnerability allows access to the entire WordPress installation data.
Recommendations Versions prior to 2.7.1 should be updated to address this issue.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1104

Produtos afetados

Fastdup
Wordpress