CVE-2026-0604
Unknown Unknown - Not Provided
Path Traversal in FastDup WordPress Plugin Allows Data Exposure

Publication date: 2026-01-06

Last updated on: 2026-01-06

Assigner: Wordfence

Description
The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.7 via the 'dir_path' parameter in the 'njt-fastdup/v1/template/directory-tree' REST API endpoint. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary directories on the server, which can contain sensitive information.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-06
Last Modified
2026-01-06
Generated
2026-06-16
AI Q&A
2026-01-06
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
njt fastdup to 2.7 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-0604 is a Path Traversal vulnerability in the FastDup WordPress plugin (up to version 2.7) that affects the 'dir_path' parameter in the 'njt-fastdup/v1/template/directory-tree' REST API endpoint. Authenticated users with Contributor-level access or higher can exploit this flaw to read arbitrary directories on the server by manipulating the directory path parameter, potentially exposing sensitive information stored on the server. [2]

Impact Analysis

This vulnerability allows an attacker with Contributor-level or higher access to read contents of arbitrary directories on the server hosting the WordPress site. This can lead to exposure of sensitive information such as configuration files, user data, or other confidential files, which may compromise the security and privacy of the website and its users. [2]

Detection Guidance

To detect this vulnerability, you can monitor REST API requests to the endpoint '/njt-fastdup/v1/template/directory-tree' that include the 'dir_path' parameter. Since the vulnerability involves path traversal via this parameter, look for requests where 'dir_path' contains suspicious patterns or attempts to access directories outside the intended scope. You can use tools like curl to test the endpoint if you have authenticated access with Contributor-level permissions or higher. Example command to test (replace URL and authentication accordingly): curl -X GET 'https://yourwordpresssite.com/wp-json/njt-fastdup/v1/template/directory-tree?dir_path=../../' -H 'Authorization: Bearer <token>' -v. Additionally, review your web server logs or use intrusion detection systems to flag unusual directory access patterns via this REST API endpoint. [2]

Mitigation Strategies

Immediate mitigation steps include: 1) Restrict access to the FastDup plugin's REST API endpoints to only trusted users with appropriate permissions (Contributor-level or higher). 2) Update the FastDup plugin to a version later than 2.7 that addresses this vulnerability, if available. 3) If an update is not yet available, consider disabling the FastDup plugin or restricting access to the vulnerable REST API endpoint '/njt-fastdup/v1/template/directory-tree' via web server rules or firewall to prevent exploitation. 4) Monitor logs for suspicious activity targeting this endpoint. 5) Review and tighten user roles and capabilities to minimize the number of users who can access this API. [2]

Compliance Impact

The vulnerability allows authenticated attackers with Contributor-level access and above to read arbitrary directories on the server, potentially exposing sensitive information. This unauthorized access to sensitive data could lead to non-compliance with data protection regulations such as GDPR and HIPAA, which require strict controls on access to personal and sensitive information. Therefore, exploitation of this vulnerability may result in violations of these standards due to unauthorized data disclosure. [2]

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-0604. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart