CVE-2026-77009: WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console
The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Update the plugin configuration/role checks to prevent subscribers (and any non-admin authenticated users) from accessing the debugging console that executes user-supplied PHP code.
WatchMan-Site7 WordPress plugin debug console access control = Restrict access so only trusted administrators can access the debugging console (no authenticated non-admins such as subscribers).
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user can exploit it, including users with only the Subscriber role. An attacker does not need administrative privileges or user interaction.
What access does an attacker gain?
The exposed debugging console allows execution of attacker-supplied PHP code on the server. This can result in arbitrary code execution with high impact to confidentiality, integrity, and availability.
Which plugin versions are affected?
WatchMan-Site7 versions through 4.2.0 are affected. The supplied information identifies 3.1.1 through 4.2.0 as the affected range.