CVE-2020-36848

HIGH

CVSS v3

7.5

HIGH

EPSS Score

68.9%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of back-up files and subsequently download them.

Technical Details

CVSS v3 Vector
3.1
Published
7/12/2025
Last Modified
7/29/2025

Frequently Asked Questions

What is CVE-2020-36848?

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of back-up files and subsequently download them.

Is CVE-2020-36848 actively exploited?

Active exploitation of CVE-2020-36848 has not been confirmed. The EPSS score is 68.9%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-36848?

CVE-2020-36848 has a CVSS v3 base score of 7.5 (HIGH severity), with vector string 3.1.

Is CVE-2020-36848 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.