The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
Metrics
Affected Vendors & Products
References
History
Mon, 02 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Awesomemotive
Awesomemotive duplicator |
|
| CPEs | cpe:2.3:a:snapcreek:duplicator:*:*:*:*:pro:wordpress:*:* |
cpe:2.3:a:awesomemotive:duplicator:*:*:*:*:lite:wordpress:*:* cpe:2.3:a:awesomemotive:duplicator:*:*:*:*:pro:wordpress:*:* |
| Vendors & Products |
Snapcreek
Snapcreek duplicator |
Awesomemotive
Awesomemotive duplicator |
Wed, 22 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Status: PUBLISHED
Assigner: mitre
Published: 2020-04-13T21:20:00.000Z
Updated: 2026-01-12T20:20:55.122Z
Reserved: 2020-04-13T00:00:00.000Z
Link: CVE-2020-11738
Updated: 2024-08-04T11:41:59.578Z
Status : Analyzed
Published: 2020-04-13T22:15:10.660
Modified: 2026-02-02T15:06:20.273
Link: CVE-2020-11738
No data.