CVE 8.8 HIGH

FastDup – Fastest WordPress Migration & Duplicator <= 2.7.1 - Missing Authorization to Authenticated (Contributor+) Backup Creation and Download_CVE-2026-1104

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missing capability check on REST API endpoints in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to create and download full-site backup archives containing the entire WordPress installation, including database exports and configuration files.

AI Analysis

Missing capability check on REST API endpoints allows authenticated attackers to create and download full-site backup archives

Basic Information

ID CVE-2026-1104
Source Wordfence
Published Feb 12, 2026 at 14:25

Affected Product

Vendor ninjateam
Product FastDup – Fastest WordPress Migration & Duplicator
Version *
Affected Versions ninjateam FastDup – Fastest WordPress Migration & Duplicator *

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor ninjateam
Product FastDup – Fastest WordPress Migration & Duplicator
Version 2.7.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.