Description
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
Published: 2026-08-06
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Total Upkeep plugin for WordPress contains a flaw that allows unauthenticated users to bypass normal access controls. An attacker can exploit this to perform actions normally reserved for authorized administrators, potentially adding, modifying, or deleting content, settings, or files. The weakness corresponds to CWE-862, broken access control, and is rated highly severe with a CVSS score of 8.2.

Affected Systems

The vulnerability applies to the WordPress Total Upkeep plugin developed by BoldGrid, specifically all releases up to and including version 1.17.2. Versions 1.17.3 and newer are reported to contain the fix.

Risk and Exploitability

With no EPSS value available, the exploitation probability is unclear from the data, but the high CVSS score indicates a significant risk. Based on the description, it is inferred that the attacker can trigger the vulnerable functionality by sending crafted HTTP requests to the plugin’s endpoints from any network location without authentication. The vulnerability is not listed in CISA's KEV data, suggesting that there have been no confirmed public demonstrations, but the nature of the flaw warrants immediate attention.

Generated by OpenCVE AI on August 6, 2026 at 16:45 UTC.

Remediation

Vendor Solution

Update the WordPress Total Upkeep Plugin to the latest available version (at least 1.17.3).


OpenCVE Recommended Actions

  • Update the Total Upkeep plugin to version 1.17.3 or later.
  • If an upgrade is not immediately possible, disable or uninstall the plugin until a patch is applied.
  • Apply role‑based access restrictions or firewall rules to block unauthenticated access to the plugin’s endpoints, ensuring only administrators can trigger its functionalities.

Generated by OpenCVE AI on August 6, 2026 at 16:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Boldgrid
Boldgrid total Upkeep
Wordpress
Wordpress wordpress
Vendors & Products Boldgrid
Boldgrid total Upkeep
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
Title WordPress Total Upkeep plugin <= 1.17.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Boldgrid Total Upkeep
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T16:08:39.359Z

Reserved: 2026-07-27T14:01:16.156Z

Link: CVE-2026-66708

cve-icon Vulnrichment

Updated: 2026-08-06T16:08:34.605Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T15:17:23.793

Modified: 2026-08-12T20:58:37.847

Link: CVE-2026-66708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T17:15:01Z

Weaknesses