← back to popular plugins
wordfence / plugin · boldgrid-backup

Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid

boldgrid-backup
total installs
50,000
total vulns
2
critical
0
high
1
medium
1
low
0
latest vuln
patched
2
unpatched
0
avg time to patch
vulnerabilities (2)
Total Upkeep <= 1.17.1 - Missing Authorization to Unauthenticated Rollback Cancellation
medium ✓ patched
cvss score 5.3
cwe CWE-862: Missing Authorization
published Apr 30, 2026
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_cli_cancel' function in all versions up to, and including, 1.17.1. This makes it possible for unauthenticated attackers to cancel a pending rollback, potentially preventing a WordPress installation from automatically reverting a failed update.
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command Injection
high ✓ patched
cvss score 7.2
cwe CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
published Mar 25, 2025
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.10 via the compression_level setting. This is due to the plugin using the compression_level setting in proc_open() without any validation. This makes it possible for authenticated attackers, with administrator-level access and above, to execute code on the server.