CVE-2020-11738
KEV PoC ×3massUnauthenticated Directory Traversal File Read in WordPress Duplicator Plugin
CISA: WordPress Snap Creek Duplicator Plugin File Download Vulnerability
CVE-2020-11738 is a directory traversal flaw (CWE-22) in the Snap Creek Duplicator WordPress plugin before 1.3.28 and in Duplicator Pro before 3.8.7.1. An unauthenticated remote attacker can supply ../ sequences in the 'file' parameter to the duplicator_download or duplicator_init endpoints and read arbitrary files from the web server, potentially exposing sensitive files such as the WordPress configuration with database credentials. The bug carries a CVSS 3.1 score of 7.5 (high, network-exploitable with no privileges or user interaction, high confidentiality impact only) and is tracked in CISA's Known Exploited Vulnerabilities catalog. Exploitation is well established: public proof-of-concept exploits are available, Wordfence reported active attacks in 2020 against a plugin user base exceeding one million sites, and CISA added it to the KEV on 2021-11-03. EPSS assigns a 97.8% probability of exploitation within 30 days (100th percentile), so defenders should treat this as actively exploited rather than theoretical.
What to do: Upgrade the free Duplicator plugin to version 1.3.28 or later and Duplicator Pro to 3.8.7.1 or later, per vendor instructions. If updating is delayed, review webserver and admin-ajax logs for requests to duplicator_download or duplicator_init containing ../ in the file parameter, and rotate WordPress database credentials and other secrets (e.g., wp-config.php contents) if suspicious reads are found.
| Awesome Motive (Snap Creek) Duplicator (free WordPress plugin) | before 1.3.28 |
| Awesome Motive (Snap Creek) Duplicator Pro | before 3.8.7.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
- Affected
- WordPress Snap Creek Duplicator Plugin
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- awesomemotive
- Products
- duplicator
- Ecosystems
- WordPress
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N