CVE-2026-77009 affects the WatchMan-Site7 WordPress plugin through version 4.2.0. The plugin fails to restrict access to its built-in debugging console, which is capable of executing user-supplied PHP code. This misconfiguration allows any authenticated user, including low-privileged roles such as subscribers, to execute arbitrary PHP code on the server. The vulnerability is classified as a Remote Code Execution (RCE) issue rooted in improper access control. Exploitation requires only a valid authenticated session, lowering the barrier for attack significantly. The impact is critical, as full server compromise is possible. No patch version is specified in the disclosure; users are advised to remove or disable the plugin until a fix is available.