CVE-2026-0604 | FastDup Plugin up to 2.7 on WordPress REST API Endpoint directory-tree dir_path path traversal
A vulnerability has been found in FastDup Plugin up to 2.7 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality of the file njt-fastdup/v1/template/directory-tree of the component REST API Endpoint. This manipulation of the argument dir_path causes path traversal.
The identification of this vulnerability is CVE-2026-0604. It is possible to initiate the attack remotely. There is no exploit available.