Vulnerability record · CVE-2020-11738 · published 13 April 2020
CVE-2020-11738: WordPress Duplicator plugin directory traversal allows arbitrary file read
Awesomemotive · Duplicator
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) is vulnerable to directory traversal via ../ in the file parameter to duplicator_download or duplicator_init. An unauthenticated remote attacker can read arbitrary files from the web server, which can expose configuration files and credentials. The flaw affects a widely deployed plugin and has been actively exploited in the wild.
Description
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityThe vulnerability is unauthenticated, remotely exploitable, listed in CISA KEV with active exploitation, and has an extremely high EPSS score, making it an urgent patching priority.
What it is
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) is vulnerable to directory traversal via ../ in the file parameter to duplicator_download or duplicator_init. An unauthenticated remote attacker can read arbitrary files from the web server, which can expose configuration files and credentials. The flaw affects a widely deployed plugin and has been actively exploited in the wild.
Impact
An attacker gains read access to arbitrary files on the server, including wp-config.php and other sensitive data. This can lead to credential theft and further compromise of the WordPress site and its database.
Attack surface
Reachable over the network through HTTP requests to the vulnerable duplicator_download or duplicator_init endpoints, with no authentication or user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
CVE-2020-11738 is listed in CISA KEV (added 2021-11-03) and has a very high EPSS probability of 0.97822 (99.9th percentile); multiple references are tagged Exploit, and Wordfence reported active attacks.
What to do
- Update the Duplicator plugin to version 1.3.28 or later (Duplicator Pro to 3.8.7.1 or later) immediately.
- If patching is not possible, disable or remove the Duplicator plugin until it can be updated.
- Restrict access to the duplicator_download and duplicator_init endpoints at the web server or WAF level.
- Rotate any credentials or secrets that may have been exposed in files readable via the traversal.
- Monitor for and investigate any signs of unauthorized file access or follow-on compromise.
Detection
- Search web server and WAF logs for requests to duplicator_download or duplicator_init containing ../ sequences in the file parameter.
- Look for HTTP requests with encoded traversal patterns (e.g., %2e%2e%2f) targeting Duplicator endpoints.
- Monitor for unusual access to sensitive files such as wp-config.php from external sources.
- Review file integrity and access logs for unexpected reads of configuration or backup files.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-11738 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "WordPress Snap Creek Duplicator Plugin File Download Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-11738 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-11738), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.