Impact
The WebTotem Backups WordPress plugin before version 1.1.0 fails to validate user‐supplied file paths, does not verify the user’s capability, and discards the outcome of its CSRF check. Consequently, any authenticated user, for example a subscriber, can delete arbitrary files on the server. Deleting core files or site assets can lead to full site takeover. This flaw is a Path Traversal vulnerability classified as CWE‑73.
Affected Systems
This vulnerability affects the WebTotem Backups plugin for WordPress, specifically all releases before version 1.1.0.
Risk and Exploitability
Based on the description, the likely attack vector is an authenticated exploit that relies on the plugin’s lack of input validation and capability checks. The CVSS score of 9.6 indicates a critical severity, and the EPSS score is < 1% and the vulnerability is not listed in KEV. However, the potential for site takeover by a low‑privilege user means the risk to any affected WordPress installation is high. The absence of a publicly reported exploit does not diminish the severity of the impact, which includes loss of confidentiality, integrity, and availability of the site.
OpenCVE Enrichment