PT-2026-7851 · WordPress · Wordpress+1
Athiwat Tiprasaharn
+2
·
Published
2026-02-12
·
Updated
2026-02-12
·
CVE-2026-1104
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FastDup – Fastest WordPress Migration & Duplicator plugin versions up to 2.7.1
Description
The FastDup plugin for WordPress is affected by a flaw that allows unauthorized backup creation and download. This is due to a missing capability check on REST API endpoints. Authenticated attackers with Contributor-level access or higher can create and download full-site backup archives, including database exports and configuration files. The affected API endpoints are not explicitly specified, but the issue relates to REST API functionality. The vulnerability allows access to the entire WordPress installation data.
Recommendations
Versions prior to 2.7.1 should be updated to address this issue.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fastdup
Wordpress