CVE-2021-47977
The Anti-Malware Security and Brute-Force Firewall plugin up to version 4.20.59 suffers from a directory traversal flaw that enables unauthenticated users to access arbitrary files on the server. An attacker can exploit this by crafting malicious requests to the duplicator_download action through admin-ajax.php, using path traversal techniques to navigate beyond the restricted directory and retrieve sensitive files. This vulnerability remains unpatched in all current versions of the plugin.
Based on public CVE data (MITRE/NVD).