WordPress · Watchman-Site7 · CVE-2026-77009
**Name of the Vulnerable Software and Affected Versions**
WatchMan-Site7 versions prior to 4.2.1
**Description**
An issue exists in the debugging console of the WatchMan-Site7 plugin due to improper code generation management. The console fails to restrict access, allowing any authenticated user, such as a subscriber, to execute arbitrary PHP code on the server.
**Recommendations**
Update the plugin to version 4.2.1 or later.