Home/CVEs/CVE-2020-11738/

CVE-2020-11738 - WordPress Snap Creek Duplicator Plugin File Download Vulnerability

Project:WordPress

Product:Snap Creek Duplicator Plugin

Date Added:2021-11-03Due Date:2022-05-03

Vulnerability Name

WordPress Snap Creek Duplicator Plugin File Download Vulnerability

Description

WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro.

Known To Be Used in Ransomware Campaigns?

Unknown

Action

Apply updates per vendor instructions.

Additional Notes

https://nvd.nist.gov/vuln/detail/CVE-2020-11738