CRITICAL 9.6 CVE-2026-77006 Published 12 Sept 2026

WordPress WebTotem Backups File Deletion Vulnerability

Worried this affects one of your servers?

The WebTotem Backups WordPress plugin, up to version 1.0.1, contains a critical security flaw.

WordPress users are at risk due to the plugin's failure to validate user-supplied file paths, check user capabilities, and disregard its own CSRF check.

This allows any authenticated user, even a low-privilege subscriber, to delete arbitrary files on the server, potentially leading to a full site takeover.

Reference: CVE-2026-77006 on NVD

← Back to Security News