Duplicator before 1.3.28 and Duplicator Pro before 3.8.7.1 let unauthenticated attackers read any file on the server. It is being exploited; update now.
Affected component: Duplicator Pro (plugin)
Fixed in: 3.8.7.1
Known exploited: this CVE is listed in the CISA Known Exploited Vulnerabilities catalog.
PowerSEC coverage: PowerSEC detects the affected versions on every plan, and has since October 2, 2026. No PowerSEC firewall rule blocks this attack. Update each affected component to its fixed version to remove the vulnerability.
Full advisory, including detection steps and remediation: https://powersec.io/vulnerability/cve-2020-11738