PT-2026-7851 · WordPress · Wordpress+1
Athiwat Tiprasaharn
+2
·
Publicado
2026-02-12
·
Atualizado
2026-02-12
·
CVE-2026-1104
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FastDup – Fastest WordPress Migration & Duplicator plugin versions up to 2.7.1
Description
The FastDup plugin for WordPress is affected by a flaw that allows unauthorized backup creation and download. This is due to a missing capability check on REST API endpoints. Authenticated attackers with Contributor-level access or higher can create and download full-site backup archives, including database exports and configuration files. The affected API endpoints are not explicitly specified, but the issue relates to REST API functionality. The vulnerability allows access to the entire WordPress installation data.
Recommendations
Versions prior to 2.7.1 should be updated to address this issue.
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fastdup
Wordpress