Executive brief
The Snap Creek Duplicator and Duplicator Pro plugins for WordPress are vulnerable to directory traversal via the file parameter in the duplicator_download or duplicator_init functions. This allows unauthenticated attackers to perform arbitrary file downloads from the WordPress dashboard.
Affected products
- Snap Creek Duplicator Pro before 3.8.7.1
- Snap Creek Duplicator before 1.3.28
Timeline
- 2020-02-24: exploited: Wordfence reported active attacks in the wild.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2021-11-03: disclosed: NVD publication date.