CVE-2023-6592
FastDup – Fastest WordPress Migration & Duplicator < 2.2 - Directory Listing to Account Takeover and Sensitive Data Exposure
Record summary
CVE-2023-6592 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 16, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FastDupDefault status: unaffected | CVE List | Before 2.2 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress FastDup <= 2.1.9 Sensitive Information Exposure - Directory ListingCVSS 5.3
FastDup WordPress plugin < 2.2 contains a directory listing vulnerability caused by lack of access restrictions in sensitive directories, letting attackers view export files, exploit requires no authentication.
Impact
Attackers can access sensitive export files, potentially leading to information disclosure.
Remediation
Update to version 2.2 or later.
Source: ProjectDiscovery