CVE-2026-3143: Total Upkeep <= 1.17.1 - Missing Authorization to Unauthenticated Rollback Cancellation
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpajaxclicancel' function in all versions up to, and including, 1.17.1. This makes it possible for unauthenticated attackers to cancel a pending rollback, potentially preventing a WordPress installation from automatically reverting a failed update.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3143?
The severity of CVE-2026-3143 is categorized as a medium risk due to unauthorized data modification potential.
How do I fix CVE-2026-3143?
To fix CVE-2026-3143, update the Total Upkeep plugin to version 1.17.2 or later.
What type of vulnerability is CVE-2026-3143?
CVE-2026-3143 is an authorization vulnerability that allows unauthorized rollback cancellations.
Which versions of Total Upkeep are affected by CVE-2026-3143?
Total Upkeep versions up to and including 1.17.1 are affected by CVE-2026-3143.
What is the impact of CVE-2026-3143 on my WordPress site?
The impact of CVE-2026-3143 could allow unauthorized users to cancel rollbacks, potentially compromising data integrity.