The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-77006 represents a critical privilege escalation and file deletion vulnerability in the WebTotem Backups WordPress plugin affecting versions through 1.0.1. The vulnerability stems from three compounding security failures: absence of file path validation, missing capability checks, and a non-functional CSRF token implementation. This combination allows any authenticated user—including low-privileged subscribers with minimal WordPress permissions—to delete arbitrary files from the server. The impact extends beyond simple file loss; attackers can systematically remove critical WordPress core files, plugin files, theme files, or configuration files to achieve complete site compromise or denial of service. Organizations using this plugin are at immediate risk regardless of their WordPress user management practices, as the traditional access control model is completely bypassed.
While CVE-2026-77006 does not map to specific MITRE ATT&CK techniques in its current classification, Casky's security skills would detect the attack patterns underlying this vulnerability through detection logic spanning multiple tactical domains. Practitioners using Casky would identify indicators associated with CWE-73 (External Control of File Name or Path) through behavioral analysis of file system operations initiated through web requests, capability validation failures, and CSRF token bypass attempts. The platform's 754 mapped skills would surface detection patterns related to unauthorized file system access, privilege escalation attempts by low-privileged users, and anomalous WordPress administrative function calls originating from subscriber-level accounts. Practitioners would see findings highlighting unauthenticated or under-authenticated requests triggering destructive file operations, missing input validation on file path parameters, and web application control flow bypasses—enabling teams to identify both vulnerable plugin configurations and active exploitation attempts before catastrophic data loss occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-77006. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation