BoldGrid Vulnerabilities and Affected Products
Vulnerabilities associated with Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid.
Products
Clear product- W3 Total Cache14 vulnerabilities
- Client Invoicing by Sprout Invoices8 vulnerabilities
- Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid6 vulnerabilities
- Post and Page Builder by BoldGrid5 vulnerabilities
- Post and Page Builder by BoldGrid – Visual Drag and Drop Editor5 vulnerabilities
- Sprout Clients4 vulnerabilities
- BoldGrid Easy SEO – Simple and Effective SEO2 vulnerabilities
- Total Upkeep2 vulnerabilities
- total_upkeep2 vulnerabilities
- weForms2 vulnerabilities
- weForms – Easy Drag & Drop Contact Form Builder For WordPress2 vulnerabilities
- Help Scout1 vulnerability
- w3_total_cache1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-3143MEDIUM | Total Upkeep <= 1.17.1 - Missing Authorization to Unauthenticated Rollback CancellationThe Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_cli_cancel' function in all versions up to, and including, 1.17.1. This makes it possible for unauthenticated attackers to cancel a pending rollback, potentially preventing a WordPress installation from automatically reverting a failed update. CWE-862May 1, 2026 | CVSS5.3v3.1 | EPSS0.257% | PoCs3 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-36848HIGH | Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup DownloadThe Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of back-up files and subsequently download them. CWE-200Jul 12, 2025 | CVSS7.5v3.1 | EPSS1.1% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-2257HIGH | Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command InjectionThe Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.10 via the compression_level setting. This is due to the plugin using the compression_level setting in proc_open() without any validation. This makes it possible for authenticated attackers, with administrator-level access and above, to execute code on the server. CWE-78Mar 26, 2025 | CVSS7.2v3.1 | EPSS0.791% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-13907MEDIUM | Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.8 - Authenticated (Administrator+) Server-Side Request ForgeryThe Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.16.8 via the 'download' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. CWE-918Feb 27, 2025 | CVSS4.9v3.1 | EPSS0.452% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-9461HIGH | Total Upkeep <= 1.16.6 - Authenticated (Administrator+) Remote Code Execution via Backup SettingsThe Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.6 via the cron_interval parameter. This is due to missing input validation and sanitization. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server. CWE-78Nov 26, 2024 | CVSS7.2v3.1 | EPSS1.01% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-4932MEDIUM | Total Upkeep <= 1.14.13 - Missing Authorization to Authenticated (Subscriber+) Information DisclosureThe Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissions and above to retrieve back-up paths that can subsequently be used to download the back-up. CWE-862Mar 7, 2023 | CVSS4.3v3.1 | EPSS0.572% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |