The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of back-up files and subsequently download them.
Metrics
Affected Vendors & Products
References
History
Tue, 29 Jul 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Boldgrid
Boldgrid total Upkeep |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:boldgrid:total_upkeep:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Boldgrid
Boldgrid total Upkeep |
Mon, 14 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Sat, 12 Jul 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of back-up files and subsequently download them. | |
| Title | Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download | |
| Weaknesses | CWE-200 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-07-12T11:23:39.932Z
Updated: 2025-07-14T20:11:20.429Z
Reserved: 2025-07-11T21:29:23.975Z
Link: CVE-2020-36848
Updated: 2025-07-14T14:40:05.416Z
Status : Analyzed
Published: 2025-07-12T12:15:24.897
Modified: 2025-07-29T20:38:40.720
Link: CVE-2020-36848
No data.