VYPR
High severity7.5NVD Advisory· Published Jul 12, 2025· Updated Jun 17, 2026

CVE-2020-36848

CVE-2020-36848

Description

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of back-up files and subsequently download them.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:boldgrid:total_upkeep:*:*:*:*:*:wordpress:*:*
    Range: <1.14.10
  • WordPress/Total Upkeepllm-fuzzy2 versions
    <=1.14.9+ 1 more
    • (no CPE)range: <=1.14.9
    • (no CPE)
  • boldgrid/Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGridv5
    Range: 0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.