Unrated severityNVD Advisory· Published Sep 12, 2026
CVE-2026-77006
CVE-2026-77006
Description
The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <=1.0.1
- Range: <=1.0.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.