
⚠️ CISA KEV UPDATE | high confidence CVE-2020-11738 added to CISA KEV The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter, allowing unauthenticated attackers to read arbitrary files. ACTIVE EXPLOITATION CONFIRMED Source: CISA KEV | Reliability: A Link: https://nvd.nist.gov/vuln/detail/CVE-2020-11738 #CVE #CISA #KEV #threatintel #infosec
Post summary
CISA KEV update confirms active exploitation of CVE-2020-11738, a directory traversal flaw in the Snap Creek Duplicator WordPress plugin, allowing unauthenticated file reads.
