← WordPress Vulnerabilities
WordPress security by component

WebTotem Backups

WebTotem Backups (webtotem-backups) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 9.6.

Plugin slug: webtotem-backups

CVE-2026-77006: WebTotem Backups lets subscribers delete arbitrary server files

WebTotem Backups through 1.0.1 passes a caller-controlled path to file deletion without validating the path or checking user capability, and it discards the result of its CSRF check. Any authenticated user, including a subscriber, can delete arbitrary server files and potentially take over the site. The authoritative export does not name the action or path parameter.

PublishedSep 12, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for webtotem-backups
Safe version
Sep 12, 2026 CVE-2026-77006
WebTotem Backups lets subscribers delete arbitrary server files
WebTotem Backups through 1.0.1 passes a caller-controlled path to file deletion without validating the path or checking user capability, and it discards the result of its CSRF check. Any authenticated user, including a subscriber, can delete arbitrary server files and potentially take over the site. The authoritative export does not name the action or path parameter.
See mitigation notes
CVE9.6
NVDPending