CVE-2026-1104
published 2026-02-12CVE-2026-1104: The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missing…
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.28%
20.3th percentile
The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missing capability check on REST API endpoints in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to create and download full-site backup archives containing the entire WordPress installation, including database exports and configuration files.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ninjateam | fastdup_fastest_wordpress_migration_duplicator | <= 2.7.1 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat2.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x64q-5pj8-ccxv: The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missin
ghsa_unreviewed·2026-02-12
CVE-2026-1104 [HIGH] CWE-862 GHSA-x64q-5pj8-ccxv: The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missin
The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missing capability check on REST API endpoints in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to create and download full-site backup archives containing the entire WordPress installation, including database exports and configuration files.
Red Hat
operator-sdk-builder: operator-sdk-builder: No automated dependency-update configuration for submodules or Containerfile
vendor_redhat·2026-09-08·CVSS 2.6
CVE-2026-87056 [LOW] CWE-1104 operator-sdk-builder: operator-sdk-builder: No automated dependency-update configuration for submodules or Containerfile
operator-sdk-builder: operator-sdk-builder: No automated dependency-update configuration for submodules or Containerfile
A flaw was found in operator-sdk-builder. The repository lacks automated dependency-update configurations for its git submodules, Containerfile base image, and Tekton bundle references. This absence prevents the automatic flagging of stale or vulnerable dependencies. Consequently, this could lead to the inclusion of known vulnerable components in the build process, increasing the risk of security exposures.
Statement: This issue has a Low impact as it describes the absence of automated dependency update configurations within the `operator-sdk-builder` component of Konflux CI. This lack of automation means that stale or vulnerable dependencies may not be automatically i
Red Hat
operator-foundry: operator-foundry: No automated dependency-update or vulnerability-scanning configuration
vendor_redhat·2026-09-08·CVSS 2.6
CVE-2026-87052 [LOW] CWE-1104 operator-foundry: operator-foundry: No automated dependency-update or vulnerability-scanning configuration
operator-foundry: operator-foundry: No automated dependency-update or vulnerability-scanning configuration
A flaw was found in operator-foundry. The absence of automated dependency-update and vulnerability-scanning configurations in the repository increases the risk of undetected security vulnerabilities. This lack of automated security checks could potentially lead to the inclusion of known vulnerable components, which might then be exploited by an attacker if those underlying vulnerabilities are present and exploitable.
Statement: This issue has a Low impact as it describes the absence of automated dependency updates and vulnerability scanning within the `operator-foundry` component's development process. This does not represent a direct runtime vulnerability in Red Hat products but ra
Red Hat
Perl: Compress::Raw::Zlib: zlib: Perl: Multiple vulnerabilities due to an outdated vendored zlib library
vendor_redhat·2026-03-29·CVSS 2.9
CVE-2026-4176 [LOW] CWE-1104 Perl: Compress::Raw::Zlib: zlib: Perl: Multiple vulnerabilities due to an outdated vendored zlib library
Perl: Compress::Raw::Zlib: zlib: Perl: Multiple vulnerabilities due to an outdated vendored zlib library
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib.
Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.
A flaw was found in Perl, stemming from its inclusion of an outdated `Compress::Raw::Zlib` module. This module bundles a vulnerable version of the `zlib` library, which is known to contain multiple securit
Red Hat
compress-raw-zlib: Compress::Raw::Zlib: Vulnerabilities due to outdated zlib library
vendor_redhat·2026-03-05·CVSS 2.9
CVE-2026-3381 [LOW] CWE-1104 compress-raw-zlib: Compress::Raw::Zlib: Vulnerabilities due to outdated zlib library
compress-raw-zlib: Compress::Raw::Zlib: Vulnerabilities due to outdated zlib library
Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib.
Compress::Raw::Zlib includes a copy of the zlib library. Compress::Raw::Zlib version 2.220 includes zlib 1.3.2, which addresses findings fron the 7ASecurity audit of zlib. The includes fixs for CVE-2026-27171.
A flaw was found in Compress::Raw::Zlib. This component bundles an outdated version of the zlib compression library, which contains known security vulnerabilities. An attacker could potentially exploit these underlying zlib vulnerabilities through Compress::Raw::Zlib, leading to unspecified security impacts.
Statement: This has been rated as moderate as the older version of zlib only has two known flaws,
No detection rules found.
No public exploits indexed.
2026-02-12
Published