Junglewise Threat Intelligence

CVE-2026-52703: FastDup Path Traversal in WordPress plugin

CVE-2026-52703 · Severity: critical · CVSS 9.6 · Published 2026-06-15

Executive brief

FastDup, a WordPress plugin used for site duplication and migration, contains a critical security flaw. An unauthenticated attacker could potentially access or manipulate sensitive files on the web server by tricking an administrator into clicking a malicious link. This could lead to a full site takeover, data theft, or complete service disruption.

Technical details

FastDup versions 2.7.2 and below are vulnerable to a Path Traversal vulnerability (CWE-35). The flaw allows unauthenticated attackers to bypass directory restrictions to read or write files outside of the intended folder. While the vulnerability is reachable over the network without authentication, the CVSS vector indicates that successful exploitation requires user interaction, such as a privileged user clicking a crafted link. This can lead to remote code execution or sensitive information disclosure. The issue is resolved in version 2.7.3.

Affected products

  • FastDup FastDup <= 2.7.2

Timeline

  • 2026-04-20: other: Reported by researcher R2D2
  • 2026-06-12: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References