ZeroHour

CVE-2020-11738

KEV PoC ×3mass

Unauthenticated Directory Traversal File Read in WordPress Duplicator Plugin

CISA: WordPress Snap Creek Duplicator Plugin File Download Vulnerability

CVSS 3.1
7.5 high
EPSS
98%p100
Published
()
KEV added
AI analysis

CVE-2020-11738 is a directory traversal flaw (CWE-22) in the Snap Creek Duplicator WordPress plugin before 1.3.28 and in Duplicator Pro before 3.8.7.1. An unauthenticated remote attacker can supply ../ sequences in the 'file' parameter to the duplicator_download or duplicator_init endpoints and read arbitrary files from the web server, potentially exposing sensitive files such as the WordPress configuration with database credentials. The bug carries a CVSS 3.1 score of 7.5 (high, network-exploitable with no privileges or user interaction, high confidentiality impact only) and is tracked in CISA's Known Exploited Vulnerabilities catalog. Exploitation is well established: public proof-of-concept exploits are available, Wordfence reported active attacks in 2020 against a plugin user base exceeding one million sites, and CISA added it to the KEV on 2021-11-03. EPSS assigns a 97.8% probability of exploitation within 30 days (100th percentile), so defenders should treat this as actively exploited rather than theoretical.

What to do: Upgrade the free Duplicator plugin to version 1.3.28 or later and Duplicator Pro to 3.8.7.1 or later, per vendor instructions. If updating is delayed, review webserver and admin-ajax logs for requests to duplicator_download or duplicator_init containing ../ in the file parameter, and rotate WordPress database credentials and other secrets (e.g., wp-config.php contents) if suspicious reads are found.

Affected
Awesome Motive (Snap Creek) Duplicator (free WordPress plugin)before 1.3.28
Awesome Motive (Snap Creek) Duplicator Probefore 3.8.7.1
Estimated exposure
mass≈1,000,000+ WordPress sites — Wordfence reported at the time of the active attacks that the Duplicator plugin was installed on over 1 million WordPress sites, and the free plugin has historically shown 1M+ active installs.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.

CISA Known Exploited Vulnerability
Affected
WordPress Snap Creek Duplicator Plugin
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
awesomemotive
Products
duplicator
Ecosystems
WordPress
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news