Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.
The vulnerability classified as CWE-35 (path traversal) consists of insufficient validation of file paths in requests directed to the FastDup plugin. An attacker can construct a specially crafted HTTP request containing traversal sequences (e.g., '../'), which allow bypassing the allowed directory. The attack does not require having an account or any privileges in the application, but requires user interaction (UI:R). The vulnerability has a scope extending beyond the plugin component (S:C — scope change).
An attacker can gain unauthorized access to operating system or web server files outside the webroot directory, which may lead to disclosure of sensitive data (e.g., configurations, keys), file modification, or service disruption.
The FastDup plugin should be updated to a version higher than 2.7.2. Detailed information about the available patch version can be found in the manufacturer's references published by Patchstack.
WordPress FastDup plugin in versions 2.7.2 and earlier
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H