LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-11738: WordPress Snap Creek Duplicator Plugin File Download Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-11738 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their…

CVE-2020-11738 is a file download vulnerability in the WordPress Snap Creek Duplicator plugin (including Duplicator Pro). When an administrator creates a new copy of their site, the plugin can leave generated backup or package files reachable in a way that lets an attacker download them. Those packages often contain full site content, configuration, and credentials, so unauthorized access can expose sensitive data and open a path to further compromise. Defenders should treat this as a high-priority inventory and patch issue on any WordPress estate that uses the plugin.

How it works

The weakness is classified as CWE-22 (improper limitation of a pathname to a restricted directory). In practical terms, the plugin’s packaging workflow produces archive or installer files that are intended for the site administrator. Because of insufficient controls on how those files are named, stored, or requested, an unauthenticated or low-privilege attacker can request and retrieve the generated files. The CISA summary states that the vulnerability appears when an administrator creates a new copy of the site and that an attacker can then download the generated files from the WordPress environment. Exact request paths, parameters, and conditions must be confirmed against the vendor advisory; do not rely on third-party write-ups alone. Successful abuse yields the backup package itself, which commonly includes database dumps, wp-config.php contents, and other secrets.

Am I affected? How to find it in your systems

The affected software is the Snap Creek Duplicator plugin for WordPress, both the free Duplicator edition and Duplicator Pro. It is typically installed on WordPress sites used for migration, backup, or cloning workflows and appears under the plugins directory or in the WordPress admin plugins list.

How to remediate

Patch first. Apply the updates published by the vendor for Duplicator and Duplicator Pro exactly as described in the official advisory and in the CISA required action (“Apply updates per vendor instructions”). After updating:

If you can't patch immediately

If an immediate update is not possible, reduce exposure with compensating controls while you schedule the patch:

If your data may have been exposed

Actively exploited file-download flaws in backup and migration plugins frequently lead to full site compromise and credential theft. If packages may have been retrieved, assume database contents and configuration secrets are at risk: rotate all related credentials, review account and file integrity, and follow your incident-response process. You can also run a free exposure scan of your email addresses against known breach data to see whether associated credentials have appeared in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedWordPress · Snap Creek Duplicator Plugin
WeaknessCWE-22
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities