CVE-2020-36848

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of back-up files and subsequently download them.
Configurations

Configuration 1 (hide)

cpe:2.3:a:boldgrid:total_upkeep:*:*:*:*:*:wordpress:*:*

History

29 Jul 2025, 20:38

Type Values Removed Values Added
First Time Boldgrid
Boldgrid total Upkeep
CPE cpe:2.3:a:boldgrid:total_upkeep:*:*:*:*:*:wordpress:*:*
CWE NVD-CWE-noinfo
References () https://plugins.trac.wordpress.org/changeset/2439376/boldgrid-backup - () https://plugins.trac.wordpress.org/changeset/2439376/boldgrid-backup - Patch
References () https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/auxiliary/scanner/http/wp_total_upkeep_downloader.rb - () https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/auxiliary/scanner/http/wp_total_upkeep_downloader.rb - Exploit
References () https://wpscan.com/vulnerability/d35c19d9-8586-4c5b-9a01-44739cbeee19/ - () https://wpscan.com/vulnerability/d35c19d9-8586-4c5b-9a01-44739cbeee19/ - Exploit, Third Party Advisory
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/86a5adaf-02b7-4b42-a048-8bc01f07656b?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/86a5adaf-02b7-4b42-a048-8bc01f07656b?source=cve - Third Party Advisory

15 Jul 2025, 13:14

Type Values Removed Values Added
Summary
  • (es) El complemento Total Upkeep – WordPress Backup Plugin más Restore & Migrate de BoldGrid para WordPress es vulnerable a la exposición de información confidencial en todas las versiones hasta la 1.14.9 incluida, a través de los archivos env-info.php y restore-info.json. Esto permite que atacantes no autenticados encuentren la ubicación de los archivos de copia de seguridad y posteriormente los descarguen.

12 Jul 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-12 12:15

Updated : 2025-07-29 20:38


NVD link : CVE-2020-36848

Mitre link : CVE-2020-36848

CVE.ORG link : CVE-2020-36848


JSON object : View

Products Affected

boldgrid

  • total_upkeep
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo