Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid < 1.17.3 - Unauthenticated Information Exposure
medium
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to 1.17.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 1.17.3
- Fixed in:
- 1.17.3
- Disclosed:
- Aug 14, 2026
CVE-2026-16253 on NVD →
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.17.2 - Missing Authorization
medium
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.17.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.17.2
- Fixed in:
- 1.17.3
- Disclosed:
- Aug 4, 2026
CVE-2026-66708 on NVD →
Total Upkeep <= 1.17.1 - Missing Authorization to Unauthenticated Rollback Cancellation
medium
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_cli_cancel' function in all versions up to, and including, 1.17.1. This makes it possible for unauthenticated attackers...
- CVSS:
- 5.3
- Affected:
- up to 1.17.1
- Fixed in:
- 1.17.2
- Disclosed:
- Apr 30, 2026
CVE-2026-3143 on NVD →
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid [boldgrid-backup] < 1.14.10
unknown
[en] The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location...
- Affected:
- up to 1.14.10
- Fixed in:
- 1.14.10
- Disclosed:
- Jul 12, 2025
CVE-2020-36848 on NVD →
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid [boldgrid-backup] < 1.14.10
unknown
- Affected:
- up to 1.14.10
- Fixed in:
- 1.14.10
- Disclosed:
- Jul 9, 2025
CVE-2025-34084 on NVD →
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command Injection
high
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.10 via the compression_level setting. This is due to the plugin using the compression_level setting in proc_open() without any validation....
- CVSS:
- 7.2
- Affected:
- up to 1.16.10
- Fixed in:
- 1.17.0
- Disclosed:
- Mar 25, 2025
CVE-2025-2257 on NVD →
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid [boldgrid-backup] < 1.16.9
unknown
[en] The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.16.8 via the 'download' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to...
- Affected:
- up to 1.16.9
- Fixed in:
- 1.16.9
- Disclosed:
- Feb 27, 2025
CVE-2024-13907 on NVD →
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.8 - Authenticated (Administrator+) Server-Side Request Forgery
medium
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.16.8 via the 'download' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make...
- CVSS:
- 4.9
- Affected:
- up to 1.16.8
- Fixed in:
- 1.16.9
- Disclosed:
- Feb 26, 2025
CVE-2024-13907 on NVD →
Total Upkeep <= 1.16.6 - Authenticated (Administrator+) Remote Code Execution via Backup Settings
high
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.6 via the cron_interval parameter. This is due to missing input validation and sanitization. This makes it possible for authenticated attac...
- CVSS:
- 7.2
- Affected:
- up to 1.16.6
- Fixed in:
- 1.16.7
- Disclosed:
- Nov 26, 2024
CVE-2024-9461 on NVD →
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid [boldgrid-backup] < 1.16.7
unknown
[en] The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.6 via the cron_interval parameter. This is due to missing input validation and sanitization. This makes it possible for authenticated...
- Affected:
- up to 1.16.7
- Fixed in:
- 1.16.7
- Disclosed:
- Nov 26, 2024
CVE-2024-9461 on NVD →
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid [boldgrid-backup] < 1.15.9
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldGrid Total Upkeep allows Relative Path Traversal.This issue affects Total Upkeep: from n/a through 1.15.8.
- Affected:
- up to 1.15.9
- Fixed in:
- 1.15.9
- Disclosed:
- May 17, 2024
CVE-2024-24869 on NVD →
Total Upkeep <= 1.15.8 - Improper Authorization to Unauthenticated Arbitrary File Download
high
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check in all versions up to, and including, 1.15.8. This makes it possible for unauthenticated attackers to download arbitrary files using the...
- CVSS:
- 7.5
- Affected:
- up to 1.15.8
- Fixed in:
- 1.15.9
- Disclosed:
- Feb 2, 2024
CVE-2024-24869 on NVD →
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid [boldgrid-backup] < 1.14.14
unknown
[en] The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissio...
- Affected:
- up to 1.14.14
- Fixed in:
- 1.14.14
- Disclosed:
- Mar 7, 2023
CVE-2022-4932 on NVD →
Total Upkeep <= 1.14.13 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure
medium
The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissions an...
- CVSS:
- 4.3
- Affected:
- up to 1.14.13
- Fixed in:
- 1.14.14
- Disclosed:
- Feb 24, 2022
CVE-2022-4932 on NVD →
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid [boldgrid-backup] < 1.14.10
unknown
Unauthenticated Backup Archive Download vulnerability found by Wadeek in WordPress Total Upkeep plugin (versions <= 1.14.9).
- Affected:
- up to 1.14.10
- Fixed in:
- 1.14.10
- Disclosed:
- Dec 15, 2020
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid [boldgrid-backup] < 1.14.10
unknown
Sensitive Data Disclosure (Server IP Address, UID etc) vulnerability found by Wadeek in WordPress Total Upkeep plugin (versions <= 1.14.9).
- Affected:
- up to 1.14.10
- Fixed in:
- 1.14.10
- Disclosed:
- Dec 15, 2020
Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download
high
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of b...
- CVSS:
- 7.5
- Affected:
- up to 1.14.9
- Fixed in:
- 1.14.10
- Disclosed:
- Dec 14, 2020
CVE-2020-36848 on NVD →
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid [boldgrid-backup] < 1.14.10
unknown
The plugin does not restrict access to a file containing sensitive information, such as the internal path of backups, which may then allow unauthenticated users to download them.
- Affected:
- up to 1.14.10
- Fixed in:
- 1.14.10
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid [boldgrid-backup] < 1.17.0
unknown
- Affected:
- up to 1.17.0
- Fixed in:
- 1.17.0
CVE-2025-2257 on NVD →
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid [boldgrid-backup] < 1.14.10
unknown
The plugin does not restrict access to a file containing sensitive information, such as the real server IP address, UID and so on, which may help attackers in further attacks.
- Affected:
- up to 1.14.10
- Fixed in:
- 1.14.10
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database