First published: Mon Apr 13 2020(Updated: )
WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Snapcreek Duplicator | <1.3.28 | |
Snapcreek Duplicator | <3.8.7.1 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11738 is a vulnerability in the WordPress Snap Creek Duplicator Plugin.
CVE-2020-11738 has a severity level of high, with a severity value of 7.5.
CVE-2020-11738 allows an attacker to download generated files from the WordPress Snap Creek Duplicator Plugin dashboard.
Versions up to and exclusive of Duplicator 1.3.28 and Dulplicator Pro 3.8.7.1 are affected by CVE-2020-11738.
To mitigate CVE-2020-11738, update the Snap Creek Duplicator Plugin to version 1.3.29 or Pro version 3.8.7.2 or later.