BoldGrid Total Upkeep WordPress Backup Plugin Missing Authorization Vulnerability in Rollback Cancellation

Vulnerability

A vulnerability exists in the Total Upkeep WordPress Backup Plugin by BoldGrid, specifically in versions through 1.17.1. The issue arises from a lack of proper capability checks in the 'wp_ajax_cli_cancel' function, allowing unauthenticated users to cancel pending rollbacks. This could disrupt the automatic update recovery process for WordPress installations.

Impact

Exploitation of this vulnerability can interfere with WordPress's update rollback process, potentially leaving a site in a failed update state.

Reproduction

To reproduce this vulnerability, an unauthenticated user can send a request to the 'wp_ajax_cli_cancel' action via the WordPress admin-ajax.php. This request can include a 'backup_id' parameter matching the current backup identifier, and a 'cli_cancel_secret' parameter with a one-time secret that was generated when the rollback was scheduled. The absence of a capability check allows the cancellation to proceed, even without authentication.

Remediation

Users are advised to update the Total Upkeep WordPress Backup Plugin to version 1.17.2 or later.

Added: May 1, 2026, 2:23 PM
Updated: May 1, 2026, 2:23 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
7.4
remediation
7.7
relevance
7.2
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.