Impact
The WebTotem Backups WordPress plugin versions up to and including 1.0.1 does not validate the file path supplied by a user, fails to verify the user’s capability, and ignores the result of its CSRF check. As a result, any authenticated user—including a subscriber—can delete arbitrary files on the server. Removing core files or site assets can allow an attacker to take complete control of the website.
Affected Systems
This vulnerability affects the WebTotem Backups plugin for WordPress, specifically all releases with a version number of 1.0.1 or earlier.
Risk and Exploitability
Based on the description, the likely attack vector is an authenticated exploit that relies on the plugin’s lack of input validation and capability checks. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, which suggests it is not a known or actively exploited weakness. However, the potential for site takeover by a low‐privilege user means the risk to any affected WordPress installation is high. The absence of a publicly reported exploit does not diminish the severity of the impact, which includes loss of confidentiality, integrity, and availability of the site.
OpenCVE Enrichment