CVE-2020-36848: Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of back-up files and subsequently download them.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36848?
CVE-2020-36848 has been rated as having a medium severity due to its potential for sensitive information exposure.
How do I fix CVE-2020-36848?
To fix CVE-2020-36848, update the Total Upkeep plugin to version 1.15.0 or later.
What kind of sensitive information is exposed in CVE-2020-36848?
CVE-2020-36848 can expose sensitive configuration information stored in env-info.php and restore-info.json files.
Who is affected by CVE-2020-36848?
CVE-2020-36848 affects all versions of the Total Upkeep plugin for WordPress up to and including version 1.14.9.
Is authentication required to exploit CVE-2020-36848?
No, CVE-2020-36848 can be exploited by unauthenticated users.