CRITICAL
9.6 CVE-2026-77006 Published 12 Sept 2026
WordPress WebTotem Backups File Deletion Vulnerability
Worried this affects one of your servers?
The WebTotem Backups WordPress plugin, up to version 1.0.1, contains a critical security flaw.
WordPress users are at risk due to the plugin's failure to validate user-supplied file paths, check user capabilities, and disregard its own CSRF check.
This allows any authenticated user, even a low-privilege subscriber, to delete arbitrary files on the server, potentially leading to a full site takeover.
Reference: CVE-2026-77006 on NVD
← Back to Security News