CVE · High

CVE-2020-11738 — Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 1.3.28

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-11738 Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 1.3.28 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.5 < 1.3.28 1.3.28 2020-02-28

CVE-2020-11738

The Duplicator plugin for WordPress through version 1.3.28 contains a directory traversal vulnerability in the duplicator_download() and duplicator_init() functions that can be exploited through the file parameter. An attacker without authentication can leverage this flaw to access and read any file stored on the server, potentially exposing confidential data. The vulnerability affects both free and paid versions of the plugin, with the Pro variant being vulnerable before version 3.8.7.1.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.