CVE-2020-11738Active Exploitation(awesomemotive / duplicator)

LOWCVSS 7.5 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for awesomemotive duplicator systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • duplicator

Threat summary

  • Active exploitation appears in 2 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-03-30); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
duplicator

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1Active Exploitation · 2026-03-30: 1Active Exploitation · 2026-03-31: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 103-3003-31
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Patrick Roland@DeusLogica
    Active Exploitation

    ⚠️ CISA KEV UPDATE | high confidence CVE-2020-11738 added to CISA KEV The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter, allowing unauthenticated attackers to read arbitrary files. ACTIVE EXPLOITATION CONFIRMED Source: CISA KEV | Reliability: A Link: https://nvd.nist.gov/vuln/detail/CVE-2020-11738 #CVE #CISA #KEV #threatintel #infosec

    Post summary

    CISA KEV update confirms active exploitation of CVE-2020-11738, a directory traversal flaw in the Snap Creek Duplicator WordPress plugin, allowing unauthenticated file reads.

    2000046
    311 followersView on X
  • Patrick Roland@DeusLogica
    Active Exploitation

    ⚠️ CISA KEV UPDATE | high confidence CVE-2020-11738 added to CISA KEV The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to dup ACTIVE EXPLOITATION CONFIRMED Source: CISA KEV | Reliability: A Link: https://nvd.nist.gov/vuln/detail/CVE-2020-11738 #CVE #CISA #KEV #threatintel #infosec

    Post summary

    CISA KEV confirms CVE-2020-11738—a directory traversal flaw in Snap Creek Duplicator WordPress plugin—is actively exploited in the wild, with no mention of patches or proof‑of‑concept details.

    0000036
    306 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appawesomemotiveduplicator-wordpress-
Appawesomemotiveduplicator-wordpress-

Explore more