CVE-2020-11738: WordPress Snap Creek Duplicator Plugin File Download Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 97.8% chance of exploitation in the next 30 days.
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
Affected products
- Awesomemotive Duplicator: before 1.3.28 (fixed in 1.3.28); before 3.8.7.1 (fixed in 3.8.7.1)
Published 2020-04-13. Last modified 2026-06-17.