CRITICAL 9.9 CVE-2026-77009 Published 2 Sept 2026

WordPress WatchMan-Site7 Plugin Arbitrary Code Execution

Worried this affects one of your servers?

The WatchMan-Site7 WordPress plugin, up to version 4.2.0, has a vulnerability that allows any authenticated user, such as a subscriber, to run arbitrary PHP code on the server.

This is due to the plugin not restricting access to its debugging console, which executes user-supplied PHP code.

Reference: CVE-2026-77009 on NVD

← Back to Security News