Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download
Strategic Overview
- Status
- Patched in 1.14.10
- Affected Version
<= 1.14.9- CVSS
- 7.5High
- Weakness type
- CWE-200 · Exposure of Sensitive Information to an Unauthorized Actor
- CVE
CVE-2020-36848
At a glance
CVE-2020-36848 is a high-severity Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the Total Upkeep WordPress plugin, affecting versions <= 1.14.9. It carries a CVSS score of 7.5 (reachable over the network; low attack complexity; high confidentiality impact). Exploitation requires no authentication. The issue is fixed in version 1.14.10; sites on affected versions should update now. Disclosed December 2020, reported by Wadeek.
Vulnerability Overview
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of back-up files and subsequently download them.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user. A successful exploit has high impact on confidentiality.
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Reaching this weakness in Total Upkeep <= 1.14.9 takes no account at all. Sensitive information exposure means data the application intended to keep internal is returned to a caller who should not be able to see it.
The disclosed data — credentials, tokens, customer records or internal paths — is usually worth more as material for a follow-up attack than as an end in itself. For Total Upkeep the fix is 1.14.10: builds <= 1.14.9 are affected, anything from 1.14.10 onward is not.
Remediation
Update to version 1.14.10, or a newer patched version
How does WordSec protect against this?
This one needs no account at all, which puts it outside what login hardening can reach; WordSec's login security narrows the account-level paths around it, and the firewall is what inspects the request itself. None of that substitutes for the fix: Total Upkeep 1.14.10 closes this, and updating the plugin is the step that ends it.
- Login Security
- Alerts
External References
Related records
Same weakness class
Other vulnerabilities in Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid
- 7.5CVE-2024-24869: Total Upkeep Improper Authorization
CVE-2024-24869 - 7.2CVE-2025-2257: Total Upkeep Command Injection
CVE-2025-2257 - 7.2CVE-2024-9461: Total Upkeep <= 1.16.6 Remote Code Execution
CVE-2024-9461 - 5.3CVE-2026-66708: Total Upkeep Missing Authorization
CVE-2026-66708 - 5.3CVE-2026-3143: Total Upkeep Unauthenticated Rollback Cancellation
CVE-2026-3143 - 4.9CVE-2024-13907: Total Upkeep SSRF
CVE-2024-13907 - 4.3CVE-2022-4932: Total Upkeep Authenticated (Subscriber+) Information
CVE-2022-4932
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C