Impact
The WatchMan‑Site7 WordPress plugin, up through version 4.2.0, fails to restrict access to its debugging console. Once accessed, the console executes user‑supplied PHP code, allowing any authenticated user—even a subscriber role—to run arbitrary code on the hosting server. This flaw is a classic code‑injection weakness (CWE‑94) and may lead to full server compromise.
Affected Systems
The vulnerability affects the WatchMan‑Site7 WordPress plugin, version 3.1.1 through 4.2.0. The vendor is listed as Unknown:WatchMan‑Site7, with no further vendor details available.
Risk and Exploitability
The software carries a CVSS score of 9.9, indicating critical severity. The EPSS score is not available, but the flaw permits exploitation by any logged‑in user, making the attack vector simple and readily achievable. The vulnerability is not currently listed in the CISA KEV catalog, yet the high severity and logical exploitation path warrant immediate attention.
OpenCVE Enrichment