Description

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of back-up files and subsequently download them.

INFO

Published Date :

2025-07-12T11:23:39.932Z

Last Modified :

2026-04-08T17:04:51.635Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2020-36848 vulnerability.

Vendors Products
Boldgrid
  • Total Upkeep

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact