Loading
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
Use CWE-22, Snapcreek vendor hub and Duplicator product page to widen CVE-2020-11738 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2014-9262 and CVE-2017-16815 for nearby disclosures in the same product family.