The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of back-up files and subsequently download them.
Metrics
Affected Vendors & Products
References
History
Tue, 29 Jul 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Boldgrid
Boldgrid total Upkeep |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:boldgrid:total_upkeep:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Boldgrid
Boldgrid total Upkeep |
Mon, 14 Jul 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sun, 13 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
Sat, 12 Jul 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of back-up files and subsequently download them. | |
Title | Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download | |
Weaknesses | CWE-200 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-07-12T11:23:39.932Z
Updated: 2025-07-14T20:11:20.429Z
Reserved: 2025-07-11T21:29:23.975Z
Link: CVE-2020-36848

Updated: 2025-07-14T14:40:05.416Z

Status : Analyzed
Published: 2025-07-12T12:15:24.897
Modified: 2025-07-29T20:38:40.720
Link: CVE-2020-36848

No data.