SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-77009

CRITICAL · CVSS 9.9 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The WatchMan-Site7 WordPress plugin versions up to 4.2.0 are vulnerable due to unrestricted access to its debugging console, enabling any authenticated user, including subscribers, to execute arbitrary PHP code on the server. This critical vulnerability poses a significant risk of server compromise and potential data breaches. WordPress administrators and security teams should prioritize immediate updates or mitigations to safeguard their installations.

CVE
CVE-2026-77009
Severity
CRITICAL
CVSS
9.9
EPSS
0.29%
WordPress

Original NVD Description

The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.