Junglewise Threat Intelligence

CVE-2020-11738: WordPress Snap Creek Duplicator Plugin File Download Vulnerability

CVE-2020-11738 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2021-11-03

Vendors: Wordpress.

Executive brief

The Snap Creek Duplicator and Duplicator Pro plugins for WordPress are vulnerable to directory traversal via the file parameter in the duplicator_download or duplicator_init functions. This allows unauthenticated attackers to perform arbitrary file downloads from the WordPress dashboard.

Affected products

  • Snap Creek Duplicator Pro before 3.8.7.1
  • Snap Creek Duplicator before 1.3.28

Timeline

  • 2020-02-24: exploited: Wordfence reported active attacks in the wild.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: disclosed: NVD publication date.