Executive brief
The WatchMan-Site7 WordPress plugin contains an unprotected debugging console that executes arbitrary PHP code supplied by users. Any authenticated user—even a subscriber with minimal privileges—can exploit this to run malicious code directly on the web server, potentially compromising the entire WordPress installation and underlying server. The plugin has been permanently removed from the WordPress.org directory and will not receive security updates.
Technical details
The vulnerability is a PHP code injection flaw (CWE-94) in the WatchMan-Site7 plugin's debugging console. The debugging console accepts and executes user-supplied PHP code without access controls or input validation. Attack precondition: the attacker must be an authenticated WordPress user (minimum privilege level: subscriber). The attack vector is network-based; no special configuration or user interaction is required beyond authentication. Exploitation allows remote code execution with the privileges of the web server process. No patch is available; the plugin author has announced permanent closure and will not release a fixed version. Mitigation requires complete deactivation and deletion of the plugin.
Affected products
- WatchMan-Site7 WatchMan-Site7 3.1.1 through 4.2.0
Timeline
- 2026-09-01: disclosed
- 2026-09-02: advisory