SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-77006

CRITICAL · CVSS 9.6 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The WebTotem Backups plugin for WordPress versions up to 1.0.1 is vulnerable due to inadequate validation of user-supplied file paths and insufficient checks on user capabilities, allowing authenticated users to delete arbitrary files on the server. This could lead to a complete site takeover, posing a significant risk to the integrity of WordPress installations. WordPress site administrators and security teams should prioritize updating or removing this plugin to mitigate potential exploitation.

CVE
CVE-2026-77006
Severity
CRITICAL
CVSS
9.6
EPSS
0.18%
WordPress

Original NVD Description

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.