plugin

Boldgrid Backup Vulnerabilities

20 known security issues reported for the Boldgrid Backup WordPress plugin. Most recent disclosed Aug 14, 2026.

4 high 5 medium

Running Boldgrid Backup on your site? Check whether your installed version is affected.

Scan your site free

Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid < 1.17.3 - Unauthenticated Information Exposure

medium

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to 1.17.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 1.17.3
Fixed in:
1.17.3
Disclosed:
Aug 14, 2026

CVE-2026-16253 on NVD →

Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.17.2 - Missing Authorization

medium

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.17.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.17.2
Fixed in:
1.17.3
Disclosed:
Aug 4, 2026

CVE-2026-66708 on NVD →

Total Upkeep <= 1.17.1 - Missing Authorization to Unauthenticated Rollback Cancellation

medium

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_cli_cancel' function in all versions up to, and including, 1.17.1. This makes it possible for unauthenticated attackers...

CVSS:
5.3
Affected:
up to 1.17.1
Fixed in:
1.17.2
Disclosed:
Apr 30, 2026

CVE-2026-3143 on NVD →

Total Upkeep – WordPress Backup Plugin plus Restore &amp; Migrate by BoldGrid [boldgrid-backup] < 1.14.10

unknown

[en] The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location...

Affected:
up to 1.14.10
Fixed in:
1.14.10
Disclosed:
Jul 12, 2025

CVE-2020-36848 on NVD →

Total Upkeep – WordPress Backup Plugin plus Restore &amp; Migrate by BoldGrid [boldgrid-backup] < 1.14.10

unknown
Affected:
up to 1.14.10
Fixed in:
1.14.10
Disclosed:
Jul 9, 2025

CVE-2025-34084 on NVD →

Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command Injection

high

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.10 via the compression_level setting. This is due to the plugin using the compression_level setting in proc_open() without any validation....

CVSS:
7.2
Affected:
up to 1.16.10
Fixed in:
1.17.0
Disclosed:
Mar 25, 2025

CVE-2025-2257 on NVD →

Total Upkeep – WordPress Backup Plugin plus Restore &amp; Migrate by BoldGrid [boldgrid-backup] < 1.16.9

unknown

[en] The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.16.8 via the 'download' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to...

Affected:
up to 1.16.9
Fixed in:
1.16.9
Disclosed:
Feb 27, 2025

CVE-2024-13907 on NVD →

Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.8 - Authenticated (Administrator+) Server-Side Request Forgery

medium

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.16.8 via the 'download' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make...

CVSS:
4.9
Affected:
up to 1.16.8
Fixed in:
1.16.9
Disclosed:
Feb 26, 2025

CVE-2024-13907 on NVD →

Total Upkeep <= 1.16.6 - Authenticated (Administrator+) Remote Code Execution via Backup Settings

high

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.6 via the cron_interval parameter. This is due to missing input validation and sanitization. This makes it possible for authenticated attac...

CVSS:
7.2
Affected:
up to 1.16.6
Fixed in:
1.16.7
Disclosed:
Nov 26, 2024

CVE-2024-9461 on NVD →

Total Upkeep – WordPress Backup Plugin plus Restore &amp; Migrate by BoldGrid [boldgrid-backup] < 1.16.7

unknown

[en] The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.6 via the cron_interval parameter. This is due to missing input validation and sanitization. This makes it possible for authenticated...

Affected:
up to 1.16.7
Fixed in:
1.16.7
Disclosed:
Nov 26, 2024

CVE-2024-9461 on NVD →

Total Upkeep – WordPress Backup Plugin plus Restore &amp; Migrate by BoldGrid [boldgrid-backup] < 1.15.9

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldGrid Total Upkeep allows Relative Path Traversal.This issue affects Total Upkeep: from n/a through 1.15.8.

Affected:
up to 1.15.9
Fixed in:
1.15.9
Disclosed:
May 17, 2024

CVE-2024-24869 on NVD →

Total Upkeep <= 1.15.8 - Improper Authorization to Unauthenticated Arbitrary File Download

high

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check in all versions up to, and including, 1.15.8. This makes it possible for unauthenticated attackers to download arbitrary files using the...

CVSS:
7.5
Affected:
up to 1.15.8
Fixed in:
1.15.9
Disclosed:
Feb 2, 2024

CVE-2024-24869 on NVD →

Total Upkeep – WordPress Backup Plugin plus Restore &amp; Migrate by BoldGrid [boldgrid-backup] < 1.14.14

unknown

[en] The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissio...

Affected:
up to 1.14.14
Fixed in:
1.14.14
Disclosed:
Mar 7, 2023

CVE-2022-4932 on NVD →

Total Upkeep <= 1.14.13 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure

medium

The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissions an...

CVSS:
4.3
Affected:
up to 1.14.13
Fixed in:
1.14.14
Disclosed:
Feb 24, 2022

CVE-2022-4932 on NVD →

Total Upkeep – WordPress Backup Plugin plus Restore &amp; Migrate by BoldGrid [boldgrid-backup] < 1.14.10

unknown

Unauthenticated Backup Archive Download vulnerability found by Wadeek in WordPress Total Upkeep plugin (versions <= 1.14.9).

Affected:
up to 1.14.10
Fixed in:
1.14.10
Disclosed:
Dec 15, 2020

Total Upkeep – WordPress Backup Plugin plus Restore &amp; Migrate by BoldGrid [boldgrid-backup] < 1.14.10

unknown

Sensitive Data Disclosure (Server IP Address, UID etc) vulnerability found by Wadeek in WordPress Total Upkeep plugin (versions <= 1.14.9).

Affected:
up to 1.14.10
Fixed in:
1.14.10
Disclosed:
Dec 15, 2020

Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download

high

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of b...

CVSS:
7.5
Affected:
up to 1.14.9
Fixed in:
1.14.10
Disclosed:
Dec 14, 2020

CVE-2020-36848 on NVD →

Total Upkeep – WordPress Backup Plugin plus Restore &amp; Migrate by BoldGrid [boldgrid-backup] < 1.14.10

unknown

The plugin does not restrict access to a file containing sensitive information, such as the internal path of backups, which may then allow unauthenticated users to download them.

Affected:
up to 1.14.10
Fixed in:
1.14.10

Total Upkeep – WordPress Backup Plugin plus Restore &amp; Migrate by BoldGrid [boldgrid-backup] < 1.17.0

unknown
Affected:
up to 1.17.0
Fixed in:
1.17.0

CVE-2025-2257 on NVD →

Total Upkeep – WordPress Backup Plugin plus Restore &amp; Migrate by BoldGrid [boldgrid-backup] < 1.14.10

unknown

The plugin does not restrict access to a file containing sensitive information, such as the real server IP address, UID and so on, which may help attackers in further attacks.

Affected:
up to 1.14.10
Fixed in:
1.14.10

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database