WordPress Plugin Vulnerabilities
WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console
Description
The plugin does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.
The plugin has been permanently closed on wordpress.org at the author's request, and the author has confirmed he will not be maintaining it. No fixed version will be released, and sites that still have it installed will not be offered an update. There is no setting that mitigates the issue, so the only remedy is to deactivate and delete the plugin.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
RCE
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Daniel Dhaniswara
Submitter
Daniel Dhaniswara
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-01 (about 1 day ago)
Added
2026-09-01 (about 1 day ago)
Last Updated
2026-09-01 (about 1 day ago)