CVE-2020-36848
- EPSS 60.68%
- Veröffentlicht 12.07.2025 11:23:39
- Zuletzt bearbeitet 29.07.2025 20:38:40
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This mak...
CVE-2025-34084
- EPSS 0.23%
- Veröffentlicht 09.07.2025 00:49:52
- Zuletzt bearbeitet 16.07.2025 16:15:26
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2020-36848.
CVE-2025-2257
- EPSS 0.6%
- Veröffentlicht 26.03.2025 08:21:49
- Zuletzt bearbeitet 22.05.2025 14:43:29
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.10 via the compression_level setting. This is due to the plugin using...
CVE-2024-13907
- EPSS 0.08%
- Veröffentlicht 27.02.2025 07:15:33
- Zuletzt bearbeitet 11.03.2025 16:26:05
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.16.8 via the 'download' function. This makes it possible for authe...
CVE-2024-9461
- EPSS 4.29%
- Veröffentlicht 26.11.2024 14:15:22
- Zuletzt bearbeitet 22.05.2025 14:27:29
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.6 via the cron_interval parameter. This is due to missing input valid...
CVE-2024-24869
- EPSS 1.84%
- Veröffentlicht 17.05.2024 09:15:23
- Zuletzt bearbeitet 09.06.2025 20:58:11
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldGrid Total Upkeep allows Relative Path Traversal.This issue affects Total Upkeep: from n/a through 1.15.8.
CVE-2022-4932
- EPSS 0.09%
- Veröffentlicht 07.03.2023 15:15:10
- Zuletzt bearbeitet 21.11.2024 07:36:16
The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it poss...