External risk intelligence

WebTotem Backups WordPress Plugin Arbitrary File Deletion Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-77006

The vulnerability affects a WordPress plugin, which is a component of web applications commonly deployed as public-facing websites. While it requires an authenticated user account, WordPress sites often allow public registration, making the vulnerable functionality reachable from the internet in common deployment patterns.

Cross-site Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security issue has been identified in a popular WordPress plugin that could allow unauthorized users to delete critical website files, potentially leading to a complete site compromise. This vulnerability arises from insufficient validation of user inputs and security checks within the plugin's backup functionality. The main concern is confirming if this plugin is in use and identifying any potential exposure.

  • WordPress plugin allows file deletion.
  • Impacts any authenticated user, not just administrators.
  • Confirm usage and assess exposure to related risks.

Attack Path

How an attacker could exploit the issue

An attacker with low-level access, such as a subscriber, could exploit this vulnerability. By crafting a request that bypasses security checks, they can trick the vulnerable plugin into deleting any file on the server, potentially leading to a complete takeover of the website.

  • Authenticated user access is required.
  • Arbitrary file deletion is possible.
  • Risk of complete site takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow any authenticated user to delete arbitrary files on the server when the WebTotem Backups WordPress plugin is in use. This could lead to a complete website takeover.

  • Arbitrary file deletion.
  • Authenticated user can trigger deletion.
  • Potential website takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

The WebTotem Backups WordPress plugin's ability to delete arbitrary files, even by low-privileged users, necessitates action from application owners responsible for WordPress sites. The initial step is to identify all WordPress deployments, confirm if they utilize this plugin, and assess their exposure and criticality to determine the appropriate response.

  • Application owners should investigate plugin usage.
  • Verify plugin reachability and site criticality.
  • Plan remediation based on identified risks.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the WebTotem Backups plugin used for?

WebTotem Backups is a component designed for WordPress sites to manage and store website data. It helps administrators create recovery points for their files and databases. Because it interacts directly with the server's file system to handle these backups, the plugin requires specific permissions to read and write files, which is where the security oversight exists.

What does CWE-73 mean for CVE-2026-77006?

This vulnerability is classified as CWE-73, which refers to improper control of file path references. In plain English, the plugin does not correctly verify where a file is located before acting on it. Because the plugin blindly trusts user-supplied inputs, it can be tricked into targeting and deleting essential system or configuration files instead of the backup files it is supposed to manage.

Do I need administrator privileges to trigger this bug?

No. The flaw allows even low-privileged accounts, such as standard subscribers, to execute the deletion command. While the request must be authenticated, the plugin fails to check if the user actually has the authority to perform administrative file operations. Unauthenticated users who do not have an account on the site cannot trigger this specific vulnerability.

Why is this plugin considered an external risk?

Halo Surface Signal identifies this as an external risk because the plugin is part of a web-facing application. Since WordPress sites often allow visitors to register as users, the low-privileged access required to exploit this flaw can be obtained by anyone over the internet. This accessibility makes it a primary target if your site is reachable by the public.

How should I respond to this vulnerability?

First, conduct an inventory of your WordPress environments to confirm if the WebTotem Backups plugin is currently installed. If it is, evaluate the site's criticality and determine if the plugin is strictly necessary for your operations. If the feature is not in use, remove or deactivate the plugin immediately to neutralize the risk of unauthorized file deletion.

References