plugin

Fastdup Vulnerabilities

7 known security issues reported for the Fastdup WordPress plugin. Most recent disclosed Jun 12, 2026.

1 critical 1 high 3 medium

Running Fastdup on your site? Check whether your installed version is affected.

Scan your site free

FastDup – Fastest WordPress Migration & Duplicator <= 2.7.2 - Unauthenticated Path Traversal

medium

The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.7.2. This makes it possible for unauthenticated attackers to perform actions on files outside of the originally intended directory.

CVSS:
5.3
Affected:
up to 2.7.2
Fixed in:
2.7.3
Disclosed:
Jun 12, 2026

CVE-2026-52703 on NVD →

FastDup – Fastest WordPress Migration & Duplicator <= 2.7.1 - Missing Authorization to Authenticated (Contributor+) Backup Creation and Download

high

The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missing capability check on REST API endpoints in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Contributor-level access an...

CVSS:
8.8
Affected:
up to 2.7.1
Fixed in:
2.7.2
Disclosed:
Feb 11, 2026

CVE-2026-1104 on NVD →

FastDup <= 2.7 - Authenticated (Contributor+) Path Traversal via 'dir_path' REST Parameter

medium

The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.7 via the 'dir_path' parameter in the 'njt-fastdup/v1/template/directory-tree' REST API endpoint. This makes it possible for authenticated attackers, with Contributor-level...

CVSS:
6.5
Affected:
up to 2.7
Fixed in:
2.7.1
Disclosed:
Jan 5, 2026

CVE-2026-0604 on NVD →

FastDup <= 2.1.9 - Sensitive Information Exposure via Directory Listing

critical

The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.9. This makes it possible for unauthenticated attackers to obtain exports that include sensitive information such as user password hashes.

CVSS:
9.8
Affected:
up to 2.1.9
Fixed in:
2.2.0
Disclosed:
Jan 16, 2024

CVE-2023-6592 on NVD →

FastDup &#8211; Fastest WordPress Migration &amp; Duplicator [fastdup] < 2.2.0

unknown

[en] The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files.

Affected:
up to 2.2.0
Fixed in:
2.2.0
Disclosed:
Jan 16, 2024

CVE-2023-6592 on NVD →

FastDup &#8211; Fastest WordPress Migration &amp; Duplicator [fastdup] < 2.1.8

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FastDup – Fastest WordPress Migration & Duplicator.This issue affects FastDup – Fastest WordPress Migration & Duplicator: from n/a through 2.1.7.

Affected:
up to 2.1.8
Fixed in:
2.1.8
Disclosed:
Jan 8, 2024

CVE-2023-51406 on NVD →

FastDup <= 2.1.7 - Sensitive Information Exposure via Log File

medium

The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.7 via the plugin's log file. This makes it possible for unauthenticated attackers to extract sensitive data including system and plugin configurartion

CVSS:
5.3
Affected:
up to 2.1.7
Fixed in:
2.1.8
Disclosed:
Dec 27, 2023

CVE-2023-51406 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database