CRITICAL
WebTotem
CVE published 2026-09-12
CVE-2026-77006
The WebTotem Backups WordPress plugin before 1.1.0 has a critical vulnerability allowing any authenticated user to delete arbitrary files on the server, potentially leading to site takeover. This vulnerability exists due to insufficient validation of user-supplied file paths, lack of proper user capability checks, and ignoring of CSRF checks. Affected WordPress site administrators and security teams shoul [truncated]