Home / Vulnerabilities / CVE-2020-11738
HIGH SEVERITY
CVE-2020-11738 WordPress · Snap Creek Duplicator Plugin

WordPress Snap Creek Duplicator Plugin File Download Vulnerability

Technical Severity

CVSS v3.1 Metrics

HIGH
7.5 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.0/AC:L/AV:N/A:N/C:H/I:N/PR:N/S:U/UI:N
Exploitation Likelihood

EPSS Prediction

94.28 %
Predictive Probability
Percentile Rank
99.9 th

Documented as more likely to be exploited than 99.9% of known CVEs.

Detection Date

Nov 03, 2021

Remediation Due

May 03, 2022

CISA Catalog Active

Threat Analysis

WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro.

Remediation Directive

Apply updates per vendor instructions.

External Intelligence