CVE-2026-3143: Boldgrid Total Upkeep – WordPress Backup Plugin Plus Restore & Migrate By Boldgrid

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_cli_cancel' function in all versions up to, and including, 1.17.1. This makes it possible for unauthenticated attackers to cancel a pending rollback, potentially preventing a WordPress installation from automatically reverting a failed update.

Affected products

  • Boldgrid Total Upkeep – WordPress Backup Plugin Plus Restore & Migrate By Boldgrid: up to and including 1.17.1

Published 2026-05-01. Last modified 2026-06-17.