VYPR

Total Upkeep

by WordPress

CVEs (9)

  • CVE-2026-66708HigAug 6, 2026
    risk 0.53cvss 8.2epss 0.00

    Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.

  • CVE-2026-16253HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-restore functionality and exposes it to unauthenticated users, allowing them to disclose sensitive backup information and to force a full site restore that…

  • CVE-2024-24869HigMay 17, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldGrid Total Upkeep allows Relative Path Traversal.This issue affects Total Upkeep: from n/a through 1.15.8.

  • CVE-2024-9461HigNov 26, 2024
    risk 0.47cvss 7.2epss 0.01

    The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.6 via the cron_interval parameter. This is due to missing input validation and sanitization.…

  • CVE-2020-36848HigJul 12, 2025
    risk 0.45cvss 7.5epss 0.01

    The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for…

  • CVE-2025-2257HigMar 26, 2025
    risk 0.40cvss 7.2epss 0.01

    The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.10 via the compression_level setting. This is due to the plugin using the compression_level…

  • CVE-2022-4932MedMar 7, 2023
    risk 0.28cvss 4.3epss 0.01

    The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated…

  • CVE-2026-3143MedMay 1, 2026
    risk 0.27cvss 5.3epss 0.00

    The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_cli_cancel' function in all versions up to, and including, 1.17.1. This makes…

  • CVE-2024-13907MedFeb 27, 2025
    risk 0.25cvss 4.9epss 0.00

    The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.16.8 via the 'download' function. This makes it possible for authenticated attackers, with…