WordPress Plugin Vulnerabilities

WebTotem Backups <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal

Description

The plugin does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
FILE DELETION
CWE

Miscellaneous

Original Researcher
João Ramos Maciel
Submitter
João Ramos Maciel
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-10 (about 2 days ago)
Added
2026-09-10 (about 1 day ago)
Last Updated
2026-09-10 (about 1 day ago)

Other