Executive brief
Total Upkeep is a WordPress plugin for website backup and site maintenance. This vulnerability allows unauthenticated attackers to bypass access controls and view or manipulate data they should not have permission to access, potentially exposing sensitive site information or enabling unauthorized administrative actions without requiring login credentials.
Technical details
The vulnerability is a broken access control flaw in the Total Upkeep WordPress plugin versions up to and including 1.17.2. The affected component improperly validates user permissions, allowing unauthenticated attackers to access restricted pages or perform privileged actions without authentication. The attack is network-reachable and requires no prior authentication or user interaction. Attackers can bypass authorization checks to view sensitive data or execute unauthorized operations. The vulnerability was patched in version 1.17.3 and is recommended for immediate remediation due to its high severity and potential for mass exploitation.
Affected products
- BoldGrid Total Upkeep up to 1.17.2
Timeline
- 2026-08-04: disclosed: Published on Patchstack
- 2026-08-06: advisory: NVD entry published
- 2026-08-04: patched: Version 1.17.3 released with fix