CVE-2026-77006

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-12 06:16

Updated : 2026-09-14 21:10


NVD link : CVE-2026-77006

Mitre link : CVE-2026-77006

CVE.ORG link : CVE-2026-77006


JSON object : View

Products Affected

No product.

CWE
CWE-73

External Control of File Name or Path