Remote Code Execution Vulnerability in BoldGrid Total Upkeep Plugin for WordPress
CVE-2025-2257
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 March 2025
What is CVE-2025-2257?
The Total Upkeep – WordPress Backup Plugin by BoldGrid is susceptible to a Remote Code Execution vulnerability allowing authenticated users with administrative privileges and above to execute arbitrary code on the server. This security issue arises due to the lack of validation on the compression_level setting being provided to the proc_open() function. Attackers could exploit this vulnerability to potentially compromise the server and its data, making it crucial for administrators to update to the latest version to mitigate the risk.
Affected Version(s)
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid * <= 1.16.10