Security Advisory

CVE-2026-77006

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-12 06:00:07
Last updated 2026-09-12 15:36:09
Assigner WPScan
CVSS score 9.6
State PUBLISHED

Description

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.