High
CVSS 7.5
Overview
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro...
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
This vulnerability is rated 🟠 HIGH.
Recommended actions: