← Vulnerability feed

Vulnerability record · CVE-2020-11738 · published 13 April 2020

CVE-2020-11738: WordPress Duplicator plugin directory traversal allows arbitrary file read

Awesomemotive · Duplicator

The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) is vulnerable to directory traversal via ../ in the file parameter to duplicator_download or duplicator_init. An unauthenticated remote attacker can read arbitrary files from the web server, which can expose configuration files and credentials. The flaw affects a widely deployed plugin and has been actively exploited in the wild.

7.5 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 98% · top 0.1% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
11References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityThe vulnerability is unauthenticated, remotely exploitable, listed in CISA KEV with active exploitation, and has an extremely high EPSS score, making it an urgent patching priority.

What it is

The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) is vulnerable to directory traversal via ../ in the file parameter to duplicator_download or duplicator_init. An unauthenticated remote attacker can read arbitrary files from the web server, which can expose configuration files and credentials. The flaw affects a widely deployed plugin and has been actively exploited in the wild.

Impact

An attacker gains read access to arbitrary files on the server, including wp-config.php and other sensitive data. This can lead to credential theft and further compromise of the WordPress site and its database.

Attack surface

Reachable over the network through HTTP requests to the vulnerable duplicator_download or duplicator_init endpoints, with no authentication or user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

CVE-2020-11738 is listed in CISA KEV (added 2021-11-03) and has a very high EPSS probability of 0.97822 (99.9th percentile); multiple references are tagged Exploit, and Wordfence reported active attacks.

What to do

  • Update the Duplicator plugin to version 1.3.28 or later (Duplicator Pro to 3.8.7.1 or later) immediately.
  • If patching is not possible, disable or remove the Duplicator plugin until it can be updated.
  • Restrict access to the duplicator_download and duplicator_init endpoints at the web server or WAF level.
  • Rotate any credentials or secrets that may have been exposed in files readable via the traversal.
  • Monitor for and investigate any signs of unauthorized file access or follow-on compromise.

Detection

  • Search web server and WAF logs for requests to duplicator_download or duplicator_init containing ../ sequences in the file parameter.
  • Look for HTTP requests with encoded traversal patterns (e.g., %2e%2e%2f) targeting Duplicator endpoints.
  • Monitor for unusual access to sensitive files such as wp-config.php from external sources.
  • Review file integrity and access logs for unexpected reads of configuration or backup files.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-11738 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "WordPress Snap Creek Duplicator Plugin File Download Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-11738 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-25095Awesomemotive duplicator vulnerabilityThe Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration fil…EPSS 0.92%9.8CVE-2018-17207WordPress Duplicator leftover installer files allow PHP code injection and RCESnap Creek Duplicator before 1.2.42 leaves installer.php and installer-backup.php accessible after installation. An attacker can reach those files an…EPSS 60%analysed7.5CVE-2023-6114Awesomemotive duplicator vulnerabilityThe Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` …EPSS 31%7.5CVE-2022-2551Awesomemotive duplicator vulnerabilityThe Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of t…EPSS 17%6.1CVE-2023-33309Awesomemotive duplicator cross-site scripting vulnerabilityUnauth. Reflected Cross-Site Scripting (XSS) vulnerability in Awesome Motive Duplicator Pro plugin <= 4.5.11 versions.EPSS 0.38%6.1CVE-2018-7543Awesomemotive duplicator cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote atta…EPSS 3.3%5.3CVE-2022-2552Awesomemotive duplicator missing authentication for critical function vulnerabilityThe Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as serve…EPSS 11%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%

Source: NIST National Vulnerability Database (record CVE-2020-11738), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.