CVE-2020-36848
Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download
highExposure of Sensitive Information to an Unauthorized Actor
7.5
CVSS Score
7.5
CVSS Score
high
Severity
1.14.10
Patched in
1671d
Time to patch
Description
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of back-up files and subsequently download them.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NAttack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
High
Confidentiality
None
Integrity
None
Availability
Technical Details
Affected versions
<=1.14.9PublishedDecember 14, 2020
Last updatedJuly 12, 2025
Affected pluginboldgrid-backup
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.