Description
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of back-up files and subsequently download them.
Published: 2025-07-12
Score: 7.5 High
EPSS: 68.9% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-30799 The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of back-up files and subsequently download them.
History

Tue, 29 Jul 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Boldgrid
Boldgrid total Upkeep
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:boldgrid:total_upkeep:*:*:*:*:*:wordpress:*:*
Vendors & Products Boldgrid
Boldgrid total Upkeep

Mon, 14 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0004}

epss

{'score': 0.00054}


Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0004}


Sat, 12 Jul 2025 11:30:00 +0000

Type Values Removed Values Added
Description The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of back-up files and subsequently download them.
Title Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Boldgrid Total Upkeep
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:04:51.635Z

Reserved: 2025-07-11T21:29:23.975Z

Link: CVE-2020-36848

cve-icon Vulnrichment

Updated: 2025-07-14T14:40:05.416Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-12T12:15:24.897

Modified: 2025-07-29T20:38:40.720

Link: CVE-2020-36848

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses