Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2020-11738

WordPress | Snap Creek Duplicator PluginAdded 2021-11-03Remediation Deadline 2022-05-03

WordPress Snap Creek Duplicator Plugin File Download Vulnerability

WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-22

References