Critical Vulnerability in WatchMan-Site7 WordPress Plugin Allows Arbitrary Code Execution
A critical vulnerability (CVE-2026-77009, CVSS 9.9) in the WatchMan-Site7 WordPress plugin through version 4.2.0 allows any authenticated user to execute arbitrary PHP code on the server. This vulnerability is exploitable via a debugging console that does not restrict access. Immediate action is required to protect against potential exploitation.