CVE-2026-77006 PUBLISHED

WebTotem Backups <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal

Assigner: WPScan
Reserved: 20.08.2026 Published: 12.09.2026 Updated: 12.09.2026

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.

Product Status

Vendor Unknown
Product WebTotem Backups
Versions Default: unknown
  • affected from 0 to 1.0.1 (incl.)

Credits

  • João Ramos Maciel finder
  • WPScan coordinator

References

Problem Types

  • CWE-73 External Control of File Name or Path CWE
  • CWE-352 Cross-Site Request Forgery (CSRF) CWE