CVE-2020-11738 | Snap Creek Duplicator up to 1.3.27 on WordPress duplicator_download/duplicator_init file path traversal (ID 160621)
A vulnerability classified as critical has been found in Snap Creek Duplicator up to 1.3.27 on WordPress. Affected is the function duplicator_download/duplicator_init. The manipulation of the argument file with the input ../ leads to path traversal.
This vulnerability is traded as CVE-2020-11738. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.