Junglewise Threat Intelligence

CVE-2026-16253: Bolder Backup Total Upkeep authentication bypass in backup restore

CVE-2026-16253 · Severity: high · CVSS 7.5 · Published 2026-08-12

Vendors: BoldGrid.

Executive brief

The Total Upkeep WordPress backup plugin fails to properly secure the authorization token for its backup and restore features, exposing it to unauthenticated users. An attacker can retrieve sensitive backup metadata, including the private restore token, and use it to force a complete site restoration—overwriting all live files and databases with backup data. This represents a complete loss of control over the live site and potential data loss or replacement with stale/malicious backups.

Technical details

The vulnerability is an incomplete fix for CVE-2020-36848 affecting an authentication bypass in the backup-restore mechanism. The plugin stores a backup restore authorization token (cron_secret) in a JSON configuration file accessible at `/wp-content/plugins/boldgrid-backup/cron/restore-info-*.json` without proper access controls, allowing unauthenticated HTTP GET requests to leak the secret. An attacker can then use the leaked restore ID and secret to send an unauthenticated POST request to the `boldgrid_backup_run_restore` AJAX endpoint, which validates only the secret—not user authentication—permitting a forced full site restoration. The attack requires a backup to exist (which is created by default) and is network-accessible with no user interaction. The fix in v1.17.3 only protects new sites; existing affected installations retain exposed secrets and remain at risk until manually reset.

Affected products

  • BoldGrid Total Upkeep before 1.17.3

Timeline

  • 2026-08-10: disclosed
  • 2026-08-12: patched: Version 1.17.3 released; note that existing affected sites remain at risk until secrets are manually reset

References

Related threats