Extension WordPress

Vulnérabilités Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid

Cette page rassemble les failles publiées pour Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid, leurs plages de versions affectées et les correctifs signalés dans la base locale.

7Vulnérabilités
0Critiques
7Avec correctif
7,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid

7 fiches

CVE-2026-3143 Moyenne · 5,3
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid

Total Upkeep <= 1.17.1 – Missing Authorization to Unauthenticated Rollback Cancellation

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_cli_cancel' function in all versions up to,…

Versions affectées

*-1.17.1

Correctif

1.17.2

Publication

30/04/2026

CVE-2025-2257 Élevée · 7,2
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid

Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 – Authenticated (Admin+) Command Injection

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.10 via the compression_level setting. This is due to…

Versions affectées

*-1.16.10

Correctif

1.17.0

Publication

25/03/2025

CVE-2024-13907 Moyenne · 4,9
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid

Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.8 – Authenticated (Administrator+) Server-Side Request Forgery

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.16.8 via the 'download' function. This makes it possible…

Versions affectées

*-1.16.8

Correctif

1.16.9

Publication

26/02/2025

CVE-2024-9461 Élevée · 7,2
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid

Total Upkeep <= 1.16.6 – Authenticated (Administrator+) Remote Code Execution via Backup Settings

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.6 via the cron_interval parameter. This is due to…

Versions affectées

*-1.16.6

Correctif

1.16.7

Publication

26/11/2024

CVE-2024-24869 Élevée · 7,5
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid

Total Upkeep <= 1.15.8 – Improper Authorization to Unauthenticated Arbitrary File Download

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check in all versions up to, and including, 1.15.8. This…

Versions affectées

*-1.15.8

Correctif

1.15.9

Publication

02/02/2024

CVE-2022-4932 Moyenne · 4,3
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid

Total Upkeep <= 1.14.13 – Missing Authorization to Authenticated (Subscriber+) Information Disclosure

The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for…

Versions affectées

*-1.14.13

Correctif

1.14.14

Publication

24/02/2022

CVE-2020-36848 Élevée · 7,5
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid

Total Upkeep by BoldGrid <= 1.14.9 – Unauthenticated Backup Download

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes…

Versions affectées

*-1.14.9

Correctif

1.14.10

Publication

14/12/2020

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités