Description
The WebTotem Backups WordPress plugin before 1.1.0 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
Published: 2026-09-12
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary file deletion leading to site takeover
Action: Immediate patch
AI Analysis

Impact

The WebTotem Backups WordPress plugin before version 1.1.0 fails to validate user‐supplied file paths, does not verify the user’s capability, and discards the outcome of its CSRF check. Consequently, any authenticated user, for example a subscriber, can delete arbitrary files on the server. Deleting core files or site assets can lead to full site takeover. This flaw is a Path Traversal vulnerability classified as CWE‑73.

Affected Systems

This vulnerability affects the WebTotem Backups plugin for WordPress, specifically all releases before version 1.1.0.

Risk and Exploitability

Based on the description, the likely attack vector is an authenticated exploit that relies on the plugin’s lack of input validation and capability checks. The CVSS score of 9.6 indicates a critical severity, and the EPSS score is < 1% and the vulnerability is not listed in KEV. However, the potential for site takeover by a low‑privilege user means the risk to any affected WordPress installation is high. The absence of a publicly reported exploit does not diminish the severity of the impact, which includes loss of confidentiality, integrity, and availability of the site.

Generated by OpenCVE AI on September 23, 2026 at 16:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or upgrade the WebTotem Backups plugin to version 1.1.0 or later to fix the Path Traversal flaw (CWE‑73) that enables arbitrary file deletion.
  • If a patch is not yet available, disable the backup functionality for subscriber roles or deactivate the plugin to enforce additional path validation and prevent deletion of files outside the intended directories.
  • Harden the server file system permissions so that only administrators have write access to critical directories, limiting the ability of a subscriber to delete files and mitigating the impact of the Path Traversal flaw.

Generated by OpenCVE AI on September 23, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover. The WebTotem Backups WordPress plugin before 1.1.0 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
Title WebTotem Backups <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal WebTotem Backups < 1.1.0 - Subscriber+ Arbitrary File Deletion via Path Traversal

Sat, 12 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-73
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
Title WebTotem Backups <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-23T12:09:00.467Z

Reserved: 2026-08-20T07:35:12.414Z

Link: CVE-2026-77006

cve-icon Vulnrichment

Updated: 2026-09-12T15:25:49.399Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:24.733

Modified: 2026-09-23T13:17:29.527

Link: CVE-2026-77006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T16:30:08Z

Weaknesses
  • CWE-73

    External Control of File Name or Path