vendor:
Duplicator
by:
Ramuel Gall, Hoa Nguyen - SunCSR Team
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Duplicator
Affected Version From: 1.3.24
Affected Version To: 1.3.26
Patch Exists: YES
Related CWE: CVE-2020-11738
CPE: a:snapcreek:duplicator
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WordPress
2020
WordPress Duplicator File Read Vulnerability
This module exploits an unauthenticated directory traversal vulnerability in WordPress plugin 'Duplicator' plugin version 1.3.24-1.3.26, allowing arbitrary file read with the web server privileges. This vulnerability was being actively exploited when it was discovered.
Mitigation:
Upgrade to the latest version of the Duplicator plugin (1.3.27 or later)