CVE-2020-11738: WordPress Snap Creek Duplicator Plugin File Download Vulnerability
WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro.
Other sources
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicatordownload or duplicatorinit.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-11738?
CVE-2020-11738 is a vulnerability in the WordPress Snap Creek Duplicator Plugin.
What is the severity of CVE-2020-11738?
CVE-2020-11738 has a severity level of high, with a severity value of 7.5.
How does CVE-2020-11738 affect the Snap Creek Duplicator Plugin?
CVE-2020-11738 allows an attacker to download generated files from the WordPress Snap Creek Duplicator Plugin dashboard.
Which versions of the Snap Creek Duplicator Plugin are affected by CVE-2020-11738?
Versions up to and exclusive of Duplicator 1.3.28 and Dulplicator Pro 3.8.7.1 are affected by CVE-2020-11738.
How can I mitigate the vulnerability in the Snap Creek Duplicator Plugin?
To mitigate CVE-2020-11738, update the Snap Creek Duplicator Plugin to version 1.3.29 or Pro version 3.8.7.2 or later.