WordPress Plugin Vulnerabilities

Total Upkeep < 1.17.3 - Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secret

Description

The plugin does not adequately protect the secret that authorizes its backup-restore functionality and exposes it to unauthenticated users, allowing them to disclose sensitive backup information and to force a full site restore that overwrites the live site's files and database. This is an incomplete fix of CVE-2020-36848, as the protection added at the time never took effect on distributed copies of the plugin.

Note that updating to 1.17.3 does not replace a secret that was already exposed, so a site that ran an affected version with a backup present stays at risk until its stored secret is reset.

Proof of Concept

Affects Plugins

Fixed in 1.17.3

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE
CVSS

Miscellaneous

Original Researcher
Jakub Herman
Submitter
Jakub Herman
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-08-10 (about 1 month ago)
Added
2026-08-10 (about 1 month ago)
Last Updated
2026-09-03 (about 18 days ago)

Other