Executive brief
FastDup, a WordPress plugin used for site duplication and migration, contains a critical security flaw. An unauthenticated attacker could potentially access or manipulate sensitive files on the web server by tricking an administrator into clicking a malicious link. This could lead to a full site takeover, data theft, or complete service disruption.
Technical details
FastDup versions 2.7.2 and below are vulnerable to a Path Traversal vulnerability (CWE-35). The flaw allows unauthenticated attackers to bypass directory restrictions to read or write files outside of the intended folder. While the vulnerability is reachable over the network without authentication, the CVSS vector indicates that successful exploitation requires user interaction, such as a privileged user clicking a crafted link. This can lead to remote code execution or sensitive information disclosure. The issue is resolved in version 2.7.3.
Affected products
- FastDup FastDup <= 2.7.2
Timeline
- 2026-04-20: other: Reported by researcher R2D2
- 2026-06-12: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date