PT-2026-7851 · WordPress · Wordpress+1

Athiwat Tiprasaharn

+2

·

Published

2026-02-12

·

Updated

2026-02-12

·

CVE-2026-1104

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FastDup – Fastest WordPress Migration & Duplicator plugin versions up to 2.7.1
Description The FastDup plugin for WordPress is affected by a flaw that allows unauthorized backup creation and download. This is due to a missing capability check on REST API endpoints. Authenticated attackers with Contributor-level access or higher can create and download full-site backup archives, including database exports and configuration files. The affected API endpoints are not explicitly specified, but the issue relates to REST API functionality. The vulnerability allows access to the entire WordPress installation data.
Recommendations Versions prior to 2.7.1 should be updated to address this issue.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1104

Affected Products

Fastdup
Wordpress