WordPress Plugin Vulnerabilities

WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console

Description

The plugin does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.

The plugin has been permanently closed on wordpress.org at the author's request, and the author has confirmed he will not be maintaining it. No fixed version will be released, and sites that still have it installed will not be offered an update. There is no setting that mitigates the issue, so the only remedy is to deactivate and delete the plugin.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
RCE
OWASP top 10
CWE

Miscellaneous

Original Researcher
Daniel Dhaniswara
Submitter
Daniel Dhaniswara
Verified
Yes

Timeline

Publicly Published
2026-09-01 (about 1 day ago)
Added
2026-09-01 (about 1 day ago)
Last Updated
2026-09-01 (about 1 day ago)

Other