VYPR
Unrated severityNVD Advisory· Published Jul 12, 2025· Updated Apr 8, 2026

Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download

CVE-2020-36848

Description

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of back-up files and subsequently download them.

Affected products

2
  • Range: <=1.14.9
  • boldgrid/Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGridv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.