Description
The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missing capability check on REST API endpoints in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to create and download full-site backup archives containing the entire WordPress installation, including database exports and configuration files.
Problem types
Product status
* (semver)
Timeline
| 2026-01-17: | Vendor Notified |
| 2026-02-11: | Disclosed |
Credits
Athiwat Tiprasaharn
Itthidej Aramsri
Waris Damkham
References
www.wordfence.com/...-c38c-4c78-9e15-797f3c3a4b30?source=cve
plugins.trac.wordpress.org/...cludes/Endpoint/PackageApi.php
plugins.trac.wordpress.org/changeset/3449530/