Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50311 | The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.6 via the cron_interval parameter. This is due to missing input validation and sanitization. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server. |
Tue, 26 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Boldgrid
Boldgrid total Upkeep |
|
| CPEs | cpe:2.3:a:boldgrid:total_upkeep:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Boldgrid
Boldgrid total Upkeep |
|
| Metrics |
ssvc
|
Tue, 26 Nov 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.6 via the cron_interval parameter. This is due to missing input validation and sanitization. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server. | |
| Title | Total Upkeep <= 1.16.6 - Authenticated (Administrator+) Remote Code Execution via Backup Settings | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:03:32.841Z
Reserved: 2024-10-03T08:06:58.564Z
Link: CVE-2024-9461
Updated: 2024-11-26T14:36:46.125Z
Status : Analyzed
Published: 2024-11-26T14:15:22.533
Modified: 2025-05-22T14:27:29.880
Link: CVE-2024-9461
No data.
OpenCVE Enrichment
No data.
EUVD