CVE-2026-66708

BoldGrid · Total Upkeep

The Total Upkeep plugin for WordPress contains a broken access control vulnerability that allows unauthenticated attackers to perform unauthorized actions.

Executive summary

A high-severity broken access control vulnerability in the BoldGrid Total Upkeep plugin exposes WordPress sites to unauthorized actions by unauthenticated attackers.

Vulnerability

This vulnerability, identified as CWE-862, involves a missing authorization check in the plugin. It allows unauthenticated remote attackers to interact with sensitive plugin functions due to the lack of proper capability validation.

Business impact

The vulnerability carries a CVSS score of 8.2, reflecting a significant risk of impact on site integrity and availability. An attacker could potentially manipulate backup configurations or trigger unauthorized administrative functions, leading to data loss or service disruption. Such unauthorized access undermines the security posture of the affected WordPress environment.

Remediation

Immediate Action: Update the WordPress Total Upkeep plugin to version 1.17.3 or later immediately.

Proactive Monitoring: Review WordPress administrative logs for unusual activity or unauthorized plugin configuration changes.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests targeting plugin-specific endpoints.

Exploitation status

Public Exploit Available: No confirmed public exploit is available in the provided data.

Analyst recommendation

The vulnerability is rated as high severity due to the lack of authentication requirements for exploitation. Administrators must prioritize updating the Total Upkeep plugin to version 1.17.3 to close the authorization gap and prevent potential unauthorized site management.