Summary
A Directory Traversal vulnerability, CVE-2020-11738, affects the Duplicator (Free & Pro) plugin for WordPress. This flaw allows unauthenticated attackers to read arbitrary files from the server. Affected versions include Duplicator (Free) before 1.3.28 and Duplicator Pro before 3.8.7.1. This vulnerability is being actively exploited in the wild.
Affected and patched versions
Duplicator Pro (plugin duplicator-pro): affected before 3.8.7.1; fixed in 3.8.7.1
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More (plugin duplicator): affected before 1.3.28; fixed in 1.3.28
Is my site vulnerable?
To determine if your WordPress site is vulnerable to CVE-2020-11738, you need to check the version of the Duplicator plugin installed. This vulnerability impacts Duplicator (Free) versions before 1.3.28, and Duplicator Pro versions prior to 3.8.7.1. If you are running a Duplicator (Free) version earlier than 1.3.28, or a Duplicator Pro version earlier than 3.8.7.1, your site is exposed to this vulnerability.
You can check the installed version of the Duplicator plugin through your WordPress admin dashboard. Navigate to the "Plugins" section and locate "Duplicator" or "Duplicator Pro" in the list of installed plugins. The version number is typically displayed next to the plugin name.
Alternatively, you can check the plugin's readme.txt file via FTP or your hosting provider's file manager. For Duplicator (Free), this file is usually located at /wp-content/plugins/duplicator/readme.txt. For Duplicator Pro, it is at /wp-content/plugins/duplicator-pro/readme.txt. Open the readme.txt file and look for the "Stable tag" or "Version" entry, which indicates the installed version number. Compare this version number against the patched versions listed above. If your installed version falls within the vulnerable range, your site requires immediate action.
What an attacker actually does
An attacker exploits CVE-2020-11738 by sending a specially crafted request to a WordPress website running an affected version of the Duplicator plugin. This vulnerability is a type of Directory Traversal, also known as Path Traversal. It allows an attacker to access files and directories stored outside the intended root directory of the application. The attack does not require any form of authentication, meaning an attacker can perform it without needing a username or password.
The attacker manipulates the 'file' parameter within requests sent to the duplicator_download() or duplicator_init() functions of the plugin. By inserting directory traversal sequences, such as ../, into this parameter, the attacker can bypass the plugin's intended directory restrictions. This allows them to navigate the server's file system and access files located outside the plugin's designated folders. The primary objective of such an attack is to read the contents of arbitrary files on the server.
A common target for this type of attack is the wp-config.php file. This file is critical for any WordPress installation as it contains sensitive information, including database connection details (database name, username, password, and host) and unique authentication keys and salts. If an attacker successfully downloads wp-config.php, they gain access to these credentials. This access can then be used to compromise the site's database, potentially leading to data theft, modification, or complete control over the WordPress installation. The ability to read arbitrary files with the web server's privileges poses a significant risk to the integrity and confidentiality of the entire system.
How to detect a compromise
Detecting a compromise related to CVE-2020-11738 involves reviewing web server access logs for specific patterns indicative of directory traversal attempts and successful file downloads. Since the vulnerability allows unauthenticated arbitrary file download, the primary evidence will be found in log files.
Examine your web server's access logs (e.g., Apache access.log, Nginx access.log) for requests targeting the Duplicator plugin's download or initialization functions. Look for GET requests that include duplicator_download or duplicator_init in the URL path, combined with path traversal sequences such as ../ in the file parameter.
Specific indicators of compromise include:
Requests with traversal sequences: Search for entries in your access logs that contain
GET /wp-admin/admin-ajax.php?action=duplicator_download&file=../orGET /wp-admin/admin-ajax.php?action=duplicator_init&file=../. Attackers often attempt to retrieve files likewp-config.php, so look for patterns such asfile=../../../../wp-config.php.Successful file downloads: If an attacker successfully exploited the vulnerability, you might see HTTP status codes like
200 OKassociated with requests for sensitive files. Thewp-config.phpfile is a common target. The presence ofwp-config.phpin the requested URL path within your access logs, especially when combined with traversal sequences, is a strong indicator of compromise.Unusual file access: Look for requests for other system files or configuration files that are not typically accessed by legitimate users or plugins.
You can use command-line tools like grep to search through your access logs. For example, to search for attempts to download wp-config.php using directory traversal:
grep -E "GET .*duplicator_(download|init).*file=.*\.{2,}/wp-config\.php" /var/log/apache2/access.log
grep -E "GET .*duplicator_(download|init).*file=.*\.{2,}/wp-config\.php" /var/log/nginx/access.log(Adjust log file paths as necessary for your server configuration.)
The presence of such entries suggests that an attacker has attempted to exploit or successfully exploited this vulnerability. If wp-config.php or other sensitive files were successfully downloaded, assume that database credentials and authentication keys/salts contained within those files have been compromised.
How to fix
To address CVE-2020-11738, apply the available updates immediately.
Update Duplicator (Lite): If you are using the free version of the Duplicator plugin, update to version 1.3.28 or later.
Update Duplicator Pro: If you are using Duplicator Pro, update to version 3.8.7.1 or later.
Rotate credentials: If exploitation is suspected or confirmed, rotate your WordPress database credentials (username and password) and update your authentication keys and salts in the
wp-config.phpfile.Review logs: Conduct a thorough review of your web server access logs for any signs of compromise as described in the detection section.
Temporary disablement: If immediate patching is not feasible, consider temporarily disabling the Duplicator plugin until you can apply the update. This action should be taken with an understanding of its impact on your site's backup and migration processes.
Apply vendor instructions: Always apply updates according to the vendor's official instructions.
Timeline
Date | Event |
|---|---|
2020-02-19 | Rapid7 module details published |
2020-04-13 | NVD record published |
2021-01-04 | WPScan information published |
2026-06-16 | NVD record last modified |
Sources
https://nvd.nist.gov/vuln/detail/CVE-2020-11738
https://www.wordfence.com/threat-intel/vulnerabilities/id/f9ae9aba-fa0e-4a3d-a970-e45216685cc0
https://wordpress.org/plugins/duplicator-pro/
https://nvd.nist.gov/vuln/detail/cve-2020-11738
https://wpscan.com/vulnerability/35227c3a-e893-4c68-8cb6-ffe79115fb6d/