atec Debug

atec Debug has 3 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 3 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 2 high. 2025 was the busiest year with 3 disclosures.

The most common weakness is Absolute Path Traversal, behind 2 of the records (67%). Other recurring categories include Code Injection.

Every one of the 3 issues recorded for atec Debug has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by Jonas Benjamin Friedli. atec Debug is installed on roughly 60 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all atec Debug vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.2CVE-2025-9518

atec Debug <= 1.2.22 - Authenticated (Administrator+) Arbitrary File Deletion

Read the full analysis

Vulnerability Records

3 records
atec Debug banner
Latestv1.2.38

atec Debug

docjojo

Author

docjojo

5.0(2)
100/100
Last Updated
2026-07-03 (2mo ago)
Active Installs
60+
Downloads
5,923
Requires WP
4.9+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2024-10-29 (2y ago)

atec Debug is a lightweight developer toolbox to help debug your WordPress site. Features include: * View /wp-content/debug.log directly from the admin bar * Toggle WP constants like WP_DEBUG, WP_DEBUG_LOG, SAVEQUERIES, and WP_AUTO_UPDATE_CORE * View and trigger WordPress cron jobs * Parse and edit wp-config.php values like WP_MEMORY_LIMIT * Show all database queries (when SAVEQUERIES is enabled) * List all included PHP files * Read and parse the /wp-config.php file. This plugin is ideal for development and debugging in real-time, without editing files manually. Specifications Reads and parses wp-config.php and debug.log Third-Party Services Integrity check Once, when activating the plugin, an integrity check is requested from our server – if you give your permission. Source: https://atecplugins.com/ Privacy policy: https://atecplugins.com/privacy-policy/

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C