CVE-2020-11738

The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file...

Basic Information

CVE State
PUBLISHED
Reserved Date
April 13, 2020
Published Date
April 13, 2020
Last Updated
January 12, 2026
Vendor
Snap Creek
Product
Duplicator
Description
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
Tags
wordpress cisa nuclei_scanner

CVSS Scores

CVSS v3.0

7.5 - HIGH

Vector: CVSS:3.0/AC:L/AV:N/A:N/C:H/I:N/PR:N/S:U/UI:N

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (2021-11-03 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2021-11-03 00:00:00 UTC
CISA 2021-11-03 00:00:00 UTC

Scanner Integrations

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Added to KEVIntel

  • Detected by Nuclei