WordPress Plugin Vulnerabilities
Total Upkeep < 1.17.3 - Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secret
Description
The plugin does not adequately protect the secret that authorizes its backup-restore functionality and exposes it to unauthenticated users, allowing them to disclose sensitive backup information and to force a full site restore that overwrites the live site's files and database. This is an incomplete fix of CVE-2020-36848, as the protection added at the time never took effect on distributed copies of the plugin.
Note that updating to 1.17.3 does not replace a secret that was already exposed, so a site that ran an affected version with a backup present stays at risk until its stored secret is reset.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
SENSITIVE DATA DISCLOSURE
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Jakub Herman
Submitter
Jakub Herman
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-10 (about 1 month ago)
Added
2026-08-10 (about 1 month ago)
Last Updated
2026-09-03 (about 18 days ago)