CVE-2020-11738
awesomemotive duplicator
Published 13 Apr 2020 · updated 17 Jun 2026 · Analyzed
7.5 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 3 May 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
References
- packetstormsecurity.com/files/160621/WordPress-Duplicator-1.3.26-Directory-Traversal-File-Read.html · Exploit, Third Party Advisory, VDB Entry
- packetstormsecurity.com/files/164533/WordPress-Duplicator-1.3.26-Arbitrary-File-Read.html · Exploit, Third Party Advisory, VDB Entry
- cwe.mitre.org/data/definitions/23.html · Not Applicable
- snapcreek.com/duplicator/docs/changelog/?lite · Release Notes, Vendor Advisory
- www.wordfence.com/blog/2020/02/active-attack-on-recently-patched-duplicator-plugin-vulnerability-affects-over-1-million-sites/ · Exploit, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-11738 · US Government Resource