CVE-2026-77009
nicheAuthenticated RCE in WatchMan-Site7 WordPress Plugin Debug Console
WatchMan-Site7, a WordPress site-monitoring plugin, exposes a debugging console through version 4.2.0 that is not access-restricted and executes user-supplied PHP code. Any authenticated account, even a low-privileged subscriber, can reach the console over the network and have arbitrary PHP executed on the web server. Successful exploitation yields full remote code execution with high impact to confidentiality, integrity, and availability, potentially compromising the entire site and its hosting environment (the CVSS score reflects scope change beyond the plugin). Any WordPress installation running WatchMan-Site7 4.2.0 or earlier is affected, with elevated risk on sites that allow open registration, since attackers can self-register as subscribers. No public proof-of-concept, CISA KEV listing, or confirmed exploitation is known, and the EPSS score (0.3%, 21st percentile) indicates a low probability of exploitation in the next 30 days.
What to do: Update WatchMan-Site7 to the newest release above 4.2.0 as soon as a patched version is available on wordpress.org, or deactivate the plugin until then. As an interim measure, block or restrict access to the plugin's debugging console (e.g., via WAF rules) and review whether open registration allows strangers to obtain subscriber accounts. Check web-server and WordPress logs for unexplained PHP execution, modified files, or unusual authenticated requests to the console.
| WatchMan-Site7 WordPress plugin | all versions through 4.2.0 (fixed version not specified in the source data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.
- Ecosystems
- WordPress
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.