Duplicator Directory Traversal Vulnerability (CVE-2020-11738) — High Severity

Understanding the Duplicator Directory Traversal Vulnerability

The Duplicator plugin for WordPress, a popular tool for website migration and backups, was found to have a serious security flaw. This vulnerability, identified as CVE-2020-11738, could allow attackers to access sensitive files on your web server.

At its core, this issue is a "Directory Traversal" vulnerability. Imagine your website’s file system as a tree. Normally, a plugin should only be able to access files within its own branch. However, with a directory traversal flaw, an attacker can use special sequences, like "../" (dot-dot-slash), to trick the system into moving up the file tree and accessing files or directories that are normally off-limits. For the Duplicator plugin, this attack specifically targeted the duplicator_download and duplicator_init functions, allowing unauthorized file reading.

CVE Details

This vulnerability impacts the Snap Creek Duplicator plugin, which comes in both a free "Lite" version and a paid "Pro" version for WordPress. It was officially published on April 13, 2020. The severity of this issue is rated as HIGH, and its current status is "Analyzed."

Affected Products

The following versions of the Duplicator plugin are vulnerable:

  • Snap Creek Duplicator plugin for WordPress (Lite version): All versions prior to 1.3.28
  • Snap Creek Duplicator Pro for WordPress (Pro version): All versions prior to 3.8.7.1

If you are running any version of these plugins older than the specified patched versions, your website is at risk.

Current Status

The vulnerability, CVE-2020-11738, has been thoroughly analyzed. This means security researchers and vendors have investigated the flaw, understood its mechanics, and detailed its potential impact. While the analysis is complete, the responsibility now lies with website administrators to apply the necessary updates to secure their installations.

Severity Level

Rated with a CVSS score of 7.5, this Directory Traversal vulnerability is classified as HIGH severity. A high severity rating indicates that exploiting this flaw could lead to significant consequences, such as unauthorized access to critical system files, configuration files, or even sensitive user data. Attackers could potentially gain insights into your server’s setup, which could be a stepping stone for further, more damaging attacks.

Possible Solutions

The most critical step to protect your WordPress site from this vulnerability is to update your Duplicator plugin immediately.

  • For users of the Duplicator Lite plugin, ensure you update to version 1.3.28 or newer.
  • For users of Duplicator Pro, ensure you update to version 3.8.7.1 or newer.

Regularly updating all your WordPress themes, plugins, and core installation is a fundamental cybersecurity best practice. Always back up your website before performing any updates. Staying current with software versions helps patch known vulnerabilities and protects your site from potential attacks.

References

http://packetstormsecurity.com/files/160621/WordPress-Duplicator-1.3.26-Directory-Traversal-File-Read.html

http://packetstormsecurity.com/files/164533/WordPress-Duplicator-1.3.26-Arbitrary-File-Read.html

https://cwe.mitre.org/data/definitions/23.html

https://snapcreek.com/duplicator/docs/changelog/?lite

https://www.wordfence.com/blog/2020/02/active-attack-on-recently-patched-duplicator-plugin-vulnerability-affects-over-1-million-sites/

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-11738

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.