WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid

Automated backups, remote backup to Amazon S3 and Google Drive, stop website crashes before they happen and more. Total Upkeep is the backup solution …

7Reported vulnerabilities
7.5Highest CVSS score
1.17.4Latest version
50,000+Active installs

What to do now

Update Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid to 1.17.3 or later. 7 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 3, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2020-36848 High 7.5 1.6% Before 1.14.10 1.14.10 July 12, 2025
CVE-2024-24869 High 7.5 0.7% 1.15.8 and earlier 1.15.9 February 2, 2024
CVE-2024-9461 High 7.2 1.0% Before 1.16.7 1.16.7 November 26, 2024
CVE-2024-13907 Medium 6.5 0.5% Before 1.16.9 1.16.9 February 27, 2025
CVE-2026-16253 Medium 5.3 0.3% Before 1.17.3 1.17.3 August 14, 2026
CVE-2026-66708 Medium 5.3 0.2% 1.17.2 and earlier 1.17.3 August 4, 2026
CVE-2026-3143 Medium 5.3 0.3% 0 to 1.17.1 (inclusive) 1.17.2 May 1, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.