🔐 CVE Alert

CVE-2026-77006

CRITICAL 9.6

WebTotem Backups <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal

CVSS Score
9.6
EPSS Score
0.0%
EPSS Percentile
0th

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.

Vendor unknown
Product webtotem backups
Published Sep 12, 2026
Last Updated Sep 12, 2026
Stay Ahead of the Next One

Get instant alerts for unknown webtotem backups

Be the first to know when new critical vulnerabilities affecting unknown webtotem backups are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / WebTotem Backups
0 ≤ 1.0.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/71bc08cb-681c-44bd-b6a0-bb5c58e31653/

Credits

João Ramos Maciel WPScan