Back to Database
Status published
High
CVE-2020-11738
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and...
Vulnerability Description
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-11738
Credits & Attribution
No credits recorded in the NVD database.
References
- https://snapcreek.com/duplicator/docs/changelog/?lite
- https://www.wordfence.com/blog/2020/02/active-attack-on-recently-patched-duplicator-plugin-vulnerability-affects-over-1-million-sites/
- https://cwe.mitre.org/data/definitions/23.html
- http://packetstormsecurity.com/files/160621/WordPress-Duplicator-1.3.26-Directory-Traversal-File-Read.html
- http://packetstormsecurity.com/files/164533/WordPress-Duplicator-1.3.26-Arbitrary-File-Read.html
More from awesomemotive
View All →CVE-2019-15116
The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related...
Medium
6.1
CVE-2018-7543
Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator...
Medium
6.1
CVE-2018-17207
An issue was discovered in Snap Creek Duplicator before 1.2.42....
Critical
9.8
CVE-2015-9536
The Easy Digital Downloads (EDD) Twenty-Twelve theme for WordPress, as...
Medium
6.1
CVE-2015-9535
The Easy Digital Downloads (EDD) Shoppette theme for WordPress, as...
Medium
6.1
Affected Vendor
awesomemotive
View all reports →Affected Software
duplicator
Vulnerable Versions:
0
Timeline
Official Publish:
April 13th, 2020
Last Modified:
January 12th, 2026
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.0/AC:L/AV:N/A:N/C:H/I:N/PR:N/S:U/UI:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.