CVE-2024-9461: Total Upkeep <= 1.16.6 - Authenticated (Administrator+) Remote Code Execution via Backup Settings
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.6 via the croninterval parameter. This is due to missing input validation and sanitization. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9461?
CVE-2024-9461 is classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2024-9461?
To fix CVE-2024-9461, update the Total Upkeep – WordPress Backup Plugin to version 1.16.7 or later.
What type of vulnerability is CVE-2024-9461?
CVE-2024-9461 is a remote code execution vulnerability caused by insufficient input validation.
Which versions of the plugin are affected by CVE-2024-9461?
All versions of the Total Upkeep – WordPress Backup Plugin up to and including 1.16.6 are affected by CVE-2024-9461.
Who is the vendor for CVE-2024-9461?
The vendor for CVE-2024-9461 is BoldGrid.