PatchSiren

WebTotem CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL WebTotem CVE published 2026-09-12

CVE-2026-77006

The WebTotem Backups WordPress plugin before 1.1.0 has a critical vulnerability allowing any authenticated user to delete arbitrary files on the server, potentially leading to site takeover. This vulnerability exists due to insufficient validation of user-supplied file paths, lack of proper user capability checks, and ignoring of CSRF checks. Affected WordPress site administrators and security teams shoul [truncated]