Skip to content
COOEY

EXPOSURES › CVE-2020-11738

CVE-2020-11738

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-11738 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

An unpatched file download vulnerability in the WordPress Snap Creek Duplicator Plugin allowed attackers to exfiltrate generated site files from a WordPress dashboard.

The Snap Creek Duplicator Plugin contained an unpatched file download vulnerability that let attackers access and download generated files from a WordPress dashboard. DIB organizations using WordPress with this plugin face data exfiltration risks and must patch or replace the plugin immediately. This failure highlights the danger of relying on unpatched third-party plugins in production environments.

Shame score — The vulnerability remained unpatched long enough to be actively exploited in the wild, demonstrating negligent plugin maintenance and avoidable data exposure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability in core plugin exposed sensitive file downloads, causing significant trust erosion for WordPress ecosystem.
cooey ↗ severe-fallout -0.60
Vulnerability in core plugin exposed sensitive file downloads, causing significant trust erosion for WordPress ecosystem.
"WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.