cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forfastdup fastdup

Direction: ascending
Jun 07, 2024

FastDup – Fastest WordPress Migration & Duplicator # CVE-2023-51406

CVE, Research URL

CVE-2023-51406

Date
Jan 09, 2024
Research Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FastDup – Fastest WordPress Migration & Duplicator.This issue affects FastDup – Fastest WordPress Migration & Duplicator: from n/a through 2.1.7.
Affected versions
max 2.1.8.
Status
vulnerable

FastDup – Fastest WordPress Migration & Duplicator # CVE-2023-6592

CVE, Research URL

CVE-2023-6592

Date
Jan 16, 2024
Research Description
The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files.
Affected versions
max 2.2.0.
Status
vulnerable
Apr 15, 2026

FastDup – Fastest WordPress Migration & Duplicator # CVE-2026-1104

CVE, Research URL

CVE-2026-1104

Date
Feb 12, 2026
Research Description
The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missing capability check on REST API endpoints in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to create and download full-site backup archives containing the entire WordPress installation, including database exports and configuration files.
Affected versions
max 2.7.2.
Status
vulnerable