Critical severity9.9NVD Advisory· Published Sep 2, 2026
CVE-2026-77009
CVE-2026-77009
Description
The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=4.2.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.