Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Daniel Dhaniswara

#19609of 56,331
14.7Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2026-84725
9.9
2026-09-01
WordPress · Watchman-Site7 · CVE-2026-77009
**Name of the Vulnerable Software and Affected Versions** WatchMan-Site7 versions prior to 4.2.1 **Description** An issue exists in the debugging console of the WatchMan-Site7 plugin due to improper code generation management. The console fails to restrict access, allowing any authenticated user, such as a subscriber, to execute arbitrary PHP code on the server. **Recommendations** Update the plugin to version 4.2.1 or later.
PT-2026-69364
4.8
2026-08-10
WordPress · Salon Booking System · CVE-2026-17023
**Name of the Vulnerable Software and Affected Versions** Salon Booking System versions prior to 10.30.34 **Description** The plugin fails to perform capability checks or validate the OAuth state value during the Google Calendar authorization callback. Because this callback is accessible to unauthenticated users, an attacker can overwrite the stored Google Calendar connection tokens with their own, effectively hijacking the integration. This issue is exploitable only if the site has configured its own Google OAuth client for the calendar feature. **Recommendations** Update the plugin to version 10.30.34 or later.